gem · Malicious package advisory
Malwarebip39-wordlist-utils
GHSA-q6hm-54j8-82qc
Malicious code in bip39-wordlist-utils (RubyGems)
Details
**Severity:** Critical **Affected versions:** `= 1.0.0` ## Source: amazon-inspector (4b3ac427b6e4032e434211228b95b76c556690f86e9e3ba44134e2b8525253c5) The gem declares a native C extension whose shipped source (ext/bip39-wordlist-utils/bip39-wordlist-utils.c) is an empty Init stub, so `gem install` executes extconf.rb purely as a lifecycle hook. extconf.rb decodes a base64 Ruby blob and evals it; the eval'd payload XOR-reconstructs the URL http://45.138.127.177:8092/wgkit.tar.gz (bare IP, plain HTTP, unrelated to any BIP39 purpose), double-forks a detached child, uses curl to download the tarball to /tmp/.w1.tgz, extracts to /tmp/.w1, and executes wg_install.sh as the installing user. Execution is gated by developer-targeting evasion checks: it aborts when CI env vars are set, when hostname matches sandbox/firecracker/vagrant, when the username matches scanner/analys/sandbox/tester, when CWD is under /tmp, /var/tmp, /opt/rubygems, or /workspace, or when /proc/uptime is under 1800 seconds, and only proceeds when developer artifacts (~/.ssh, ~/.gitconfig, ~/.gem/credentials, ~/.bundle, ~/.npmrc) are present. The payload then sleeps 1200-2400 seconds before firing. After the dropper logic, extconf.rb calls create_makefile to let the gem install appear to succeed. No legitimate build toolchain probing (mkmf have_header, pkg_config, try_run) is performed and no real native source is compiled. --- Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/bip39-wordlist-utils/MAL-2026-17581.json)) **References:** - https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/bip39-wordlist-utils/MAL-2026-17581.json - https://rubygems.org/gems/bip39-wordlist-utils/versions/1.0.0 - https://github.com/ossf/malicious-packages/blob/68375bfc9669351706a5a45c5039509f189d8e09/osv/malicious/rubygems/bip39-wordlist-utils/MAL-2026-17581.json - https://safedep.io/rubygems-crypto-gems-install-time-reverse-shell - https://github.com/advisories/GHSA-q6hm-54j8-82qc
Compromised versions (1)
- = 1.0.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.