VYPR

gem · Malicious package advisory

Malware

bitcion-ruby

GHSA-f4x2-825c-fcpf

Malicious code in bitcion-ruby (RubyGems)

Details

**Severity:** Critical

**Affected versions:** `= 1.0.0`

## Source: amazon-inspector (27214f874c511d94a54d727b98ceb9feaec97d4b916794a9993c430cd215fc70)
The gem 'bitcion-ruby' is a one-edit typosquat of 'bitcoin-ruby'. The library has no real functionality (lib/ exposes only a hardcoded 48-word list; ext/bitcion-ruby/bitcion-ruby.c is an empty Init stub). The native extension's ext/bitcion-ruby/extconf.rb runs at `gem install` time and, before invoking create_makefile, base64-decodes and evals a Ruby payload. The payload performs sandbox/CI/analysis-environment fingerprinting (checks for ~/.ssh, ~/.gitconfig, ~/.gem/credentials, ~/.bundle, ~/.npmrc, requires uptime > 30 minutes, excludes CI environment variables and hostnames matching patterns like 'uvm', 'firecracker', 'sandbox', rejects generated-looking usernames and /tmp or /workspace working directories). On a real developer machine, it forks a detached child that sleeps 20-40 minutes, then curls a tarball to /tmp/.w1.tgz from a URL reconstructed by XOR-decoding a hardcoded hex string with the 4-byte key 'usv\x9a' (overridable via the WG_KIT_URL env var), extracts it, and executes wg_install.sh via bash. The combination of typosquat identity, empty cover functionality, two-layer obfuscation (base64 eval + XOR-encoded URL), environment fingerprinting to evade analysis sandboxes, randomized long sleep, detached forked execution, and fetch-and-exec of a remote shell script constitutes a full install-time remote code execution against developer machines that install the gem.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/bitcion-ruby/MAL-2026-17584.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/bitcion-ruby/MAL-2026-17584.json
- https://rubygems.org/gems/bitcion-ruby/versions/1.0.0
- https://github.com/ossf/malicious-packages/blob/68375bfc9669351706a5a45c5039509f189d8e09/osv/malicious/rubygems/bitcion-ruby/MAL-2026-17584.json
- https://safedep.io/rubygems-crypto-gems-install-time-reverse-shell
- https://github.com/ossf/malicious-packages/blob/6b697dfebb1680d643ddc1cc2ee788912aa1bffa/osv/malicious/rubygems/bitcion-ruby/MAL-2026-17584.json
- https://github.com/advisories/GHSA-f4x2-825c-fcpf

Compromised versions (1)

  • = 1.0.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.