gem · Malicious package advisory
Malwarehdkey-derive-helper
GHSA-q82p-2pwq-fvp4
Malicious code in hdkey-derive-helper (RubyGems)
Details
**Severity:** Critical
**Affected versions:** `= 1.0.0`
## Source: amazon-inspector (04f5409730ece37713b6a8d3afddcce30744e213b80759f7ae89478731b0264a)
The gem presents itself as a BIP32/mnemonic derivation helper but ships only a wordlist stub and a 56-byte empty C file (ext/hdkey-derive-helper/hdkey-derive-helper.c, body `void Init_HdkeyDeriveHelper(void) {}`) registered as a native extension. Because RubyGems auto-executes `extconf.rb` during `gem install`, the extension exists solely as an execution vehicle. extconf.rb contains no build logic; it base64-decodes a Ruby payload, reconstructs a destination URL by XOR-decoding a hex blob with a 4-byte key, and in a detached `fork` downloads a tarball with curl, extracts it to /tmp/.w1, and runs `bash wg_install.sh` on the extracted contents. The reconstructed destination is http://45.138.127.89:8092/wgkit.tar.gz — a bare-IP endpoint over plain HTTP, unrelated to any publisher. Execution is gated by anti-analysis checks that refuse to run under CI environment variables, ephemeral/sandbox hostnames, generated usernames matching patterns such as uA\d+/sandbox/tester/analys/scanner, temp or analysis cwd paths, or machine uptime under 30 minutes, and that require developer artifacts (~/.ssh, ~/.gitconfig, ~/.npmrc, ~/.gem/credentials, ~/.bundle) to be present. A randomized 20–40 minute sleep further delays detonation. The combination of a cover-story crypto-wallet name, an empty native extension used purely to trigger install-time shell, multi-layer obfuscation of the C2 URL, developer-workstation targeting, and sandbox evasion is a confirmed install-time dropper against developer machines.
---
Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/hdkey-derive-helper/MAL-2026-17602.json))
**References:**
- https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/hdkey-derive-helper/MAL-2026-17602.json
- https://rubygems.org/gems/hdkey-derive-helper/versions/1.0.0
- https://github.com/ossf/malicious-packages/blob/68375bfc9669351706a5a45c5039509f189d8e09/osv/malicious/rubygems/hdkey-derive-helper/MAL-2026-17602.json
- https://safedep.io/rubygems-crypto-gems-install-time-reverse-shell
- https://github.com/ossf/malicious-packages/blob/6b697dfebb1680d643ddc1cc2ee788912aa1bffa/osv/malicious/rubygems/hdkey-derive-helper/MAL-2026-17602.json
- https://github.com/advisories/GHSA-q82p-2pwq-fvp4Compromised versions (1)
- = 1.0.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.