gem · Malicious package advisory
Malwarewallet-backup-tool
GHSA-fw9f-g4v7-9xpf
Malicious code in wallet-backup-tool (RubyGems)
Details
**Severity:** Critical
**Affected versions:** `= 1.0.0`
## Source: amazon-inspector (5452fd8e20feb6485c920b8c91f3d1f87c8bcd9f51ac9f4c57329ed9e2b20b37)
The gem's native extension build script extconf.rb, which executes automatically on `gem install`, contains a base64-encoded Ruby payload that is eval'd inside a double-forked, detached, FD-redirected child process. Before activating, the payload gates execution on absence of CI environment variables, non-ephemeral hostname, non-generated username, non-analysis working directory, machine uptime greater than 1800 seconds, and the presence of developer dotfiles (~/.ssh, ~/.gitconfig, ~/.gem/credentials, ~/.bundle). After a randomized 20-40 minute sleep, the payload reconstructs a URL by XOR-decoding a hex string, resolving to http://45.138.182.177:809/wgkit.tar.gz, then runs `curl` to fetch the tarball over plain HTTP to /tmp/.w1.tgz, extracts it, and executes wg_install.sh from the archive via bash. The accompanying C extension (wallet-backup-tool.c) is a one-line empty stub (`void Init_WalletBackupTool(void) {}`), and the shipped library exposes only a trivial ~50-word hardcoded list rather than the full BIP-39 2048-word list the package name advertises, confirming the native-extension build is a cover for the dropper rather than a real compilation step. The wallet-backup framing combined with the dotfile gating targets developers likely to hold cryptocurrency and credential material.
---
Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/wallet-backup-tool/MAL-2026-17614.json))
**References:**
- https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/wallet-backup-tool/MAL-2026-17614.json
- https://rubygems.org/gems/wallet-backup-tool/versions/1.0.0
- https://github.com/ossf/malicious-packages/blob/68375bfc9669351706a5a45c5039509f189d8e09/osv/malicious/rubygems/wallet-backup-tool/MAL-2026-17614.json
- https://safedep.io/rubygems-crypto-gems-install-time-reverse-shell
- https://github.com/ossf/malicious-packages/blob/6b697dfebb1680d643ddc1cc2ee788912aa1bffa/osv/malicious/rubygems/wallet-backup-tool/MAL-2026-17614.json
- https://github.com/advisories/GHSA-fw9f-g4v7-9xpfCompromised versions (1)
- = 1.0.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.