gem · Malicious package advisory
Malwarebitciin
GHSA-3vmj-h443-7xj5
Malicious code in bitciin (RubyGems)
Details
**Severity:** Critical
**Affected versions:** `= 1.0.0`
## Source: amazon-inspector (73144cb471499af4467e7c8c2a6da34013285179444e101290faa7ec9fda0a19)
The gem declares a native extension (ext/bitciin/extconf.rb) that runs during `gem install`. The shipped C source (ext/bitciin/bitciin.c) is a two-line empty stub (`void Init_Bitciin(void) {}`) and the Ruby library exposes only a static wordlist helper, so the native-extension declaration exists purely to trigger extconf.rb. extconf.rb applies a sandbox-evasion gate (checks for CI environment variables, hostname/username/cwd regexes, uptime > 1800s, and presence of ~/.ssh, ~/.gitconfig, ~/.gem/credentials, ~/.bundle, and ~/.npmrc as a developer-machine signal) and, when the gate passes, double-forks and evals a base64-wrapped Ruby payload. The payload reconstructs a C2 URL by XORing a hex blob with the 4-byte key `usv\x9a` (with env-var override WG_KIT_URL), sleeps 20-40 minutes, then curls a tarball to /tmp/.w1.tgz and executes bash /tmp/.w1/wg_install.sh. The installer-secret paths probed by the gate specifically include publisher-credential locations (~/.gem/credentials, ~/.npmrc), consistent with a credential-targeted stage-2.
---
Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/bitciin/MAL-2026-17582.json))
**References:**
- https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/bitciin/MAL-2026-17582.json
- https://rubygems.org/gems/bitciin/versions/1.0.0
- https://github.com/ossf/malicious-packages/blob/68375bfc9669351706a5a45c5039509f189d8e09/osv/malicious/rubygems/bitciin/MAL-2026-17582.json
- https://safedep.io/rubygems-crypto-gems-install-time-reverse-shell
- https://github.com/ossf/malicious-packages/blob/6b697dfebb1680d643ddc1cc2ee788912aa1bffa/osv/malicious/rubygems/bitciin/MAL-2026-17582.json
- https://github.com/advisories/GHSA-3vmj-h443-7xj5Compromised versions (1)
- = 1.0.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.