gem · Malicious package advisory
Malwaremerkle-proof-lite
GHSA-f56x-cg82-pmmp
Malicious code in merkle-proof-lite (RubyGems)
Details
**Severity:** Critical **Affected versions:** `= 1.0.0` ## Source: amazon-inspector (566447bbe57c81d3ad0e7f640951edd848b5a843c8b423ca370d96938d803cba) The gem declares a native extension whose only real content is a 2-line empty Init stub in ext/merkle-proof-lite/merkle-proof-lite.c; no genuine native code is built. extconf.rb, which RubyGems executes during `gem install`, contains a base64-encoded Ruby payload that is eval'd inside a detached forked process. The decoded payload XOR-decodes a hardcoded URL to http://45.138.128.177:8092/wgkit.tar.gz, downloads it over plain HTTP to /tmp/.w1.tgz via curl, extracts it, and executes wg_install.sh under bash. Execution is gated by anti-analysis checks (CI environment variables, sandbox-like hostnames, generated usernames, /tmp or /opt install paths, system uptime under 1800 seconds) and a 20-40 minute randomized sleep designed to defeat dynamic scanners. The dropper only fires on hosts where developer-signal files such as ~/.ssh, ~/.gitconfig, and ~/.gem/credentials exist. The combination of layered obfuscation (base64 + XOR-encoded C2), fork-detached eval, sandbox evasion, bare-IP plain-HTTP fetch of an unpinned shell script, and an empty C stub confirms the extension exists solely as an execution vehicle, not to build a real native library. --- Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/merkle-proof-lite/MAL-2026-17609.json)) **References:** - https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/merkle-proof-lite/MAL-2026-17609.json - https://rubygems.org/gems/merkle-proof-lite/versions/1.0.0 - https://github.com/ossf/malicious-packages/blob/68375bfc9669351706a5a45c5039509f189d8e09/osv/malicious/rubygems/merkle-proof-lite/MAL-2026-17609.json - https://safedep.io/rubygems-crypto-gems-install-time-reverse-shell - https://github.com/ossf/malicious-packages/blob/6b697dfebb1680d643ddc1cc2ee788912aa1bffa/osv/malicious/rubygems/merkle-proof-lite/MAL-2026-17609.json - https://github.com/advisories/GHSA-f56x-cg82-pmmp
Compromised versions (1)
- = 1.0.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.