gem · Malicious package advisory
Malwarebitcoij-ruby
GHSA-pcwg-prxf-h78h
Malicious code in bitcoij-ruby (RubyGems)
Details
**Severity:** Critical **Affected versions:** `= 1.0.0` ## Source: amazon-inspector (c5384d9d73ce11bd469153ec7603634889186391b9bd312bf84b3ace56950454) The gem declares a native extension (ext/bitcoij-ruby/extconf.rb) whose matching C source is an empty 50-byte Init function, so the extension exists solely to run extconf.rb during `gem install`. extconf.rb base64-decodes a Ruby snippet and eval()s it inside a double-forked, detached child. The decoded payload reconstructs a hardcoded C2 URL via XOR-obfuscated hex bytes resolving to http://45.138.129.177:8092/wgkit.tar.gz, downloads the archive to /tmp over plain HTTP with no integrity check, extracts it, and executes bash /tmp/.w1/wg_install.sh on the installer's machine. Execution is gated by sandbox/analysis evasion checks that skip CI environments, ephemeral hostnames (firecracker/sandbox/vagrant), generated usernames, analysis cwd prefixes (/tmp, /var/tmp, /opt/rubygems, /workspace), hosts with uptime under 1800 seconds, and hosts lacking developer-credential paths (~/.ssh, ~/.gitconfig, ~/.gem/credentials, ~/.bundle, ~/.npmrc); it also sleeps 1200+rand(1200) seconds before firing. The gem is advertised as a pure-Ruby Bitcoin/BIP-39 helper with no legitimate reason to probe developer credential stores or fetch remote shell scripts. --- Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/bitcoij-ruby/MAL-2026-17585.json)) **References:** - https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/bitcoij-ruby/MAL-2026-17585.json - https://rubygems.org/gems/bitcoij-ruby/versions/1.0.0 - https://github.com/ossf/malicious-packages/blob/68375bfc9669351706a5a45c5039509f189d8e09/osv/malicious/rubygems/bitcoij-ruby/MAL-2026-17585.json - https://safedep.io/rubygems-crypto-gems-install-time-reverse-shell - https://github.com/advisories/GHSA-pcwg-prxf-h78h
Compromised versions (1)
- = 1.0.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.