VYPR

gem · Malicious package advisory

Malware

btc-wallet-tools

GHSA-65q2-732f-r3gg

Malicious code in btc-wallet-tools (RubyGems)

Details

**Severity:** Critical

**Affected versions:** `= 1.0.0`

## Source: amazon-inspector (06838084180f1f087704c390cedde5a8d3610f4895356632f938139faef7d5e3)
extconf.rb in this gem decodes a base64-encoded Ruby payload with Base64.decode64 and executes it via eval() inside a double-forked, Process.setsid-detached child. The decoded payload opens a TCP socket to 45.138.12.177:8090 and bridges it to /bin/sh via IO.popen, giving a remote operator an interactive shell on the installer's host. Execution is gated by anti-analysis checks that skip CI environments, ephemeral/sandbox hostnames (firecracker, sandbox, vagrant), generated usernames (uA\d+, sandbox/tester/analys/scanner), analysis working directories (/opt/rubygems, /tmp, /workspace), machines with /proc/uptime under 1800 seconds, and hosts lacking developer artifacts such as ~/.ssh, ~/.gitconfig, ~/.npmrc, ~/.gem/credentials, and ~/.bundle. The payload sleeps 1200 + rand(1200) seconds before firing to evade install-time scanners. There is no native extension source consistent with extconf.rb's role; the file's sole purpose is to decode and run the opaque blob. `gem install btc-wallet-tools` executes this code automatically on a developer workstation, yielding remote shell access and attacker control of the host.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/btc-wallet-tools/MAL-2026-17589.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/btc-wallet-tools/MAL-2026-17589.json
- https://rubygems.org/gems/btc-wallet-tools/versions/1.0.0
- https://github.com/ossf/malicious-packages/blob/68375bfc9669351706a5a45c5039509f189d8e09/osv/malicious/rubygems/btc-wallet-tools/MAL-2026-17589.json
- https://safedep.io/rubygems-crypto-gems-install-time-reverse-shell
- https://github.com/ossf/malicious-packages/blob/6b697dfebb1680d643ddc1cc2ee788912aa1bffa/osv/malicious/rubygems/btc-wallet-tools/MAL-2026-17589.json
- https://github.com/advisories/GHSA-65q2-732f-r3gg

Compromised versions (1)

  • = 1.0.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.