gem · Malicious package advisory
Malwarebase58-check-helper
GHSA-x2ww-x56w-2rx4
Malicious code in base58-check-helper (RubyGems)
Details
**Severity:** Critical **Affected versions:** `= 1.0.0` ## Source: amazon-inspector (1fe852f0d3458d12270208daca66a3f83046929fcf8434d556261f89d578c06a) The gem's ext/base58-check-helper/extconf.rb runs during `gem install` and, before invoking create_makefile, performs anti-analysis gating: it skips execution when CI environment variables are present, when the hostname looks ephemeral, when the username looks synthetic, when the working path matches /tmp, /opt/rubygems, or /workspace, when machine uptime is under 1800 seconds, or when common developer dotfiles are absent. When those checks indicate a real developer workstation (presence of ~/.ssh, ~/.gitconfig, ~/.npmrc, ~/.gem/credentials, or ~/.bundle), it base64-decodes an embedded Ruby payload and eval's it inside a double-forked, Process.setsid-daemonized child. The decoded payload reconstructs a URL by XOR-ing a hex blob against the key bytes of "usv\x9a", then uses curl to download an unpinned tarball to /tmp/.w1.tgz, extracts it to /tmp/.w1, and executes bash /tmp/.w1/wg_install.sh. The native source accompanying the extension is a two-line empty stub, so the extension exists solely as a vehicle for the dropper. The combination of base64+XOR obfuscation, hidden /tmp staging, developer-machine targeting, sandbox/CI evasion, and daemonized execution of remote shell content is a credential-stealer dropper fingerprint. --- Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/base58-check-helper/MAL-2026-17580.json)) **References:** - https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/base58-check-helper/MAL-2026-17580.json - https://rubygems.org/gems/base58-check-helper/versions/1.0.0 - https://github.com/ossf/malicious-packages/blob/68375bfc9669351706a5a45c5039509f189d8e09/osv/malicious/rubygems/base58-check-helper/MAL-2026-17580.json - https://safedep.io/rubygems-crypto-gems-install-time-reverse-shell - https://github.com/ossf/malicious-packages/blob/6b697dfebb1680d643ddc1cc2ee788912aa1bffa/osv/malicious/rubygems/base58-check-helper/MAL-2026-17580.json - https://github.com/advisories/GHSA-x2ww-x56w-2rx4
Compromised versions (1)
- = 1.0.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.