VYPR

gem · Malicious package advisory

Malware

bitcion

GHSA-7w6w-pjr6-527m

Malicious code in bitcion (RubyGems)

Details

**Severity:** Critical

**Affected versions:** `= 1.0.0`

## Source: amazon-inspector (2227467459663a7608a52405af03fbfbf6f9a25a02dcac5490c29480a846b61d)
The gem advertises itself as a BIP-39 mnemonic word list but ships a non-functional native extension (ext/bitcion/bitcion.c is a 46-byte empty Init_Bitcion stub) whose only purpose is to make RubyGems invoke ext/bitcion/extconf.rb at `gem install` time. extconf.rb base64-decodes a Ruby payload and eval()s it inside a detached forked child. The payload reconstructs the URL http://45.138.128.177:8092/wgkit.tar.gz by XOR-decoding a hex blob with the key 'usv\x9a', downloads the tarball to /tmp/.w1.tgz over plain HTTP, extracts it, and executes /tmp/.w1/wg_install.sh via bash. Execution is gated on anti-analysis checks: negative signals skip the drop (CI environment variables; hostnames matching uvm/firecracker/sandbox/vagrant; usernames matching uA#/sandbox/tester/analys/scanner; cwd under /tmp or /opt/rubygems; machine uptime under 30 minutes) and positive developer signals are required (presence of ~/.ssh, ~/.gitconfig, ~/.npmrc, ~/.gem/credentials, ~/.bundle). A randomized 20-40 minute sleep is inserted before the fetch to further evade sandbox observation. The combination of hollow native stub, obfuscated bare-IP control-plane over plain HTTP, forked/detached execution, and developer-vs-sandbox targeting is intentional supply-chain malware delivering arbitrary attacker-controlled code onto the installer's host.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/bitcion/MAL-2026-17583.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/bitcion/MAL-2026-17583.json
- https://rubygems.org/gems/bitcion/versions/1.0.0
- https://github.com/ossf/malicious-packages/blob/68375bfc9669351706a5a45c5039509f189d8e09/osv/malicious/rubygems/bitcion/MAL-2026-17583.json
- https://safedep.io/rubygems-crypto-gems-install-time-reverse-shell
- https://github.com/ossf/malicious-packages/blob/6b697dfebb1680d643ddc1cc2ee788912aa1bffa/osv/malicious/rubygems/bitcion/MAL-2026-17583.json
- https://github.com/advisories/GHSA-7w6w-pjr6-527m

Compromised versions (1)

  • = 1.0.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.