gem · Malicious package advisory
Malwarebtc-wallet-tools
GHSA-65q2-732f-r3gg
Malicious code in btc-wallet-tools (RubyGems)
Details
**Severity:** Critical **Affected versions:** `= 1.0.0` ## Source: amazon-inspector (06838084180f1f087704c390cedde5a8d3610f4895356632f938139faef7d5e3) extconf.rb in this gem decodes a base64-encoded Ruby payload with Base64.decode64 and executes it via eval() inside a double-forked, Process.setsid-detached child. The decoded payload opens a TCP socket to 45.138.12.177:8090 and bridges it to /bin/sh via IO.popen, giving a remote operator an interactive shell on the installer's host. Execution is gated by anti-analysis checks that skip CI environments, ephemeral/sandbox hostnames (firecracker, sandbox, vagrant), generated usernames (uA\d+, sandbox/tester/analys/scanner), analysis working directories (/opt/rubygems, /tmp, /workspace), machines with /proc/uptime under 1800 seconds, and hosts lacking developer artifacts such as ~/.ssh, ~/.gitconfig, ~/.npmrc, ~/.gem/credentials, and ~/.bundle. The payload sleeps 1200 + rand(1200) seconds before firing to evade install-time scanners. There is no native extension source consistent with extconf.rb's role; the file's sole purpose is to decode and run the opaque blob. `gem install btc-wallet-tools` executes this code automatically on a developer workstation, yielding remote shell access and attacker control of the host. --- Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/btc-wallet-tools/MAL-2026-17589.json)) **References:** - https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/btc-wallet-tools/MAL-2026-17589.json - https://rubygems.org/gems/btc-wallet-tools/versions/1.0.0 - https://github.com/ossf/malicious-packages/blob/68375bfc9669351706a5a45c5039509f189d8e09/osv/malicious/rubygems/btc-wallet-tools/MAL-2026-17589.json - https://safedep.io/rubygems-crypto-gems-install-time-reverse-shell - https://github.com/ossf/malicious-packages/blob/6b697dfebb1680d643ddc1cc2ee788912aa1bffa/osv/malicious/rubygems/btc-wallet-tools/MAL-2026-17589.json - https://github.com/advisories/GHSA-65q2-732f-r3gg
Compromised versions (1)
- = 1.0.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.