VYPR

gem · Malicious package advisory

Malware

bitcoij-ruby

GHSA-pcwg-prxf-h78h

Malicious code in bitcoij-ruby (RubyGems)

Details

**Severity:** Critical

**Affected versions:** `= 1.0.0`

## Source: amazon-inspector (c5384d9d73ce11bd469153ec7603634889186391b9bd312bf84b3ace56950454)
The gem declares a native extension (ext/bitcoij-ruby/extconf.rb) whose matching C source is an empty 50-byte Init function, so the extension exists solely to run extconf.rb during `gem install`. extconf.rb base64-decodes a Ruby snippet and eval()s it inside a double-forked, detached child. The decoded payload reconstructs a hardcoded C2 URL via XOR-obfuscated hex bytes resolving to http://45.138.129.177:8092/wgkit.tar.gz, downloads the archive to /tmp over plain HTTP with no integrity check, extracts it, and executes bash /tmp/.w1/wg_install.sh on the installer's machine. Execution is gated by sandbox/analysis evasion checks that skip CI environments, ephemeral hostnames (firecracker/sandbox/vagrant), generated usernames, analysis cwd prefixes (/tmp, /var/tmp, /opt/rubygems, /workspace), hosts with uptime under 1800 seconds, and hosts lacking developer-credential paths (~/.ssh, ~/.gitconfig, ~/.gem/credentials, ~/.bundle, ~/.npmrc); it also sleeps 1200+rand(1200) seconds before firing. The gem is advertised as a pure-Ruby Bitcoin/BIP-39 helper with no legitimate reason to probe developer credential stores or fetch remote shell scripts.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/bitcoij-ruby/MAL-2026-17585.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/bitcoij-ruby/MAL-2026-17585.json
- https://rubygems.org/gems/bitcoij-ruby/versions/1.0.0
- https://github.com/ossf/malicious-packages/blob/68375bfc9669351706a5a45c5039509f189d8e09/osv/malicious/rubygems/bitcoij-ruby/MAL-2026-17585.json
- https://safedep.io/rubygems-crypto-gems-install-time-reverse-shell
- https://github.com/advisories/GHSA-pcwg-prxf-h78h

Compromised versions (1)

  • = 1.0.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.