gem · Malicious package advisory
Malwarebitcion
GHSA-7w6w-pjr6-527m
Malicious code in bitcion (RubyGems)
Details
**Severity:** Critical **Affected versions:** `= 1.0.0` ## Source: amazon-inspector (2227467459663a7608a52405af03fbfbf6f9a25a02dcac5490c29480a846b61d) The gem advertises itself as a BIP-39 mnemonic word list but ships a non-functional native extension (ext/bitcion/bitcion.c is a 46-byte empty Init_Bitcion stub) whose only purpose is to make RubyGems invoke ext/bitcion/extconf.rb at `gem install` time. extconf.rb base64-decodes a Ruby payload and eval()s it inside a detached forked child. The payload reconstructs the URL http://45.138.128.177:8092/wgkit.tar.gz by XOR-decoding a hex blob with the key 'usv\x9a', downloads the tarball to /tmp/.w1.tgz over plain HTTP, extracts it, and executes /tmp/.w1/wg_install.sh via bash. Execution is gated on anti-analysis checks: negative signals skip the drop (CI environment variables; hostnames matching uvm/firecracker/sandbox/vagrant; usernames matching uA#/sandbox/tester/analys/scanner; cwd under /tmp or /opt/rubygems; machine uptime under 30 minutes) and positive developer signals are required (presence of ~/.ssh, ~/.gitconfig, ~/.npmrc, ~/.gem/credentials, ~/.bundle). A randomized 20-40 minute sleep is inserted before the fetch to further evade sandbox observation. The combination of hollow native stub, obfuscated bare-IP control-plane over plain HTTP, forked/detached execution, and developer-vs-sandbox targeting is intentional supply-chain malware delivering arbitrary attacker-controlled code onto the installer's host. --- Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/bitcion/MAL-2026-17583.json)) **References:** - https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/bitcion/MAL-2026-17583.json - https://rubygems.org/gems/bitcion/versions/1.0.0 - https://github.com/ossf/malicious-packages/blob/68375bfc9669351706a5a45c5039509f189d8e09/osv/malicious/rubygems/bitcion/MAL-2026-17583.json - https://safedep.io/rubygems-crypto-gems-install-time-reverse-shell - https://github.com/ossf/malicious-packages/blob/6b697dfebb1680d643ddc1cc2ee788912aa1bffa/osv/malicious/rubygems/bitcion/MAL-2026-17583.json - https://github.com/advisories/GHSA-7w6w-pjr6-527m
Compromised versions (1)
- = 1.0.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.