VYPR

gem · Malicious package advisory

Malware

lighthing-invoice

GHSA-j2pr-fmc4-v7mw

Malicious code in lighthing-invoice (RubyGems)

Details

**Severity:** Critical

**Affected versions:** `= 1.0.0`

## Source: amazon-inspector (206884c57f9427c6952744828fa53861634d5451b97ba86885c701ee47ef5012)
The gem's native-extension script ext/lighthing-invoice/extconf.rb, which executes during `gem install`, base64-decodes and evals a Ruby payload. The payload reconstructs an XOR-obfuscated URL (http://45.138.132.177:8092/wgkit.tar.gz), downloads a tarball to /tmp/.w1.tgz, extracts it, and runs `bash /tmp/.w1/wg_install.sh`. The declared native source (ext/lighthing-invoice/lighthing-invoice.c) is a 55-byte empty stub with no real code, so the extension slot exists only to run the dropper. Before firing, the script applies targeting and evasion checks (CI detection, ephemeral/sandbox hostname patterns, generated analyst usernames, analysis paths, uptime threshold, presence of developer artifacts such as ~/.ssh, ~/.gitconfig, ~/.npmrc, ~/.gem/credentials, ~/.bundle), then sleeps 1200-2400 seconds and double-forks (Process.setsid, std streams redirected to /dev/null) to detach from the install process. The package name 'lighthing-invoice' is a misspelling of 'lightning-invoice' and the public Ruby API is an inert BIP-39 word-list stub, consistent with a typosquat lure whose only functional behavior is the install-time dropper. The destination is a bare IP unrelated to any declared publisher, the fetched bash is unpinned and unverified, and the URL is obfuscated to evade static detection — installing this gem executes attacker-controlled shell on the host.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/lighthing-invoice/MAL-2026-17606.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/lighthing-invoice/MAL-2026-17606.json
- https://rubygems.org/gems/lighthing-invoice/versions/1.0.0
- https://github.com/ossf/malicious-packages/blob/68375bfc9669351706a5a45c5039509f189d8e09/osv/malicious/rubygems/lighthing-invoice/MAL-2026-17606.json
- https://safedep.io/rubygems-crypto-gems-install-time-reverse-shell
- https://github.com/ossf/malicious-packages/blob/6b697dfebb1680d643ddc1cc2ee788912aa1bffa/osv/malicious/rubygems/lighthing-invoice/MAL-2026-17606.json
- https://github.com/advisories/GHSA-j2pr-fmc4-v7mw

Compromised versions (1)

  • = 1.0.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.