VYPR

gem · Malicious package advisory

Malware

bitcoin-address-utils

GHSA-pmhw-48q6-rhv3

Malicious code in bitcoin-address-utils (RubyGems)

Details

**Severity:** Critical

**Affected versions:** `= 1.0.0`

## Source: amazon-inspector (8af579a1726db72e88f7c1755ebdec49a2d0a944d0e42a0fb36566d70d751e17)
The gem's native-extension build script extconf.rb, which runs automatically during `gem install`, decodes a base64-wrapped Ruby payload that XOR-decodes a hardcoded URL (approximately http://45.13.8.12:8092/wgkit.tar.gz, overridable via ENV['WG_KIT_URL']), downloads a tarball to /tmp/.w1.tgz, extracts it, and executes the embedded wg_install.sh via bash. Execution is double-forked and detached so it survives after the install process exits. The shipped C extension source is a two-line empty stub, so the extension exists only to run the dropper. The script contains anti-analysis gating: it refuses to execute inside CI, on ephemeral or sandbox hosts, under usernames matching /uA\d+|sandbox|tester|analys|scanner/, on analysis paths such as /tmp, /var/tmp, /opt/rubygems, /workspace, and on hosts with uptime below 1800 seconds, and only detonates when developer-signal files exist (~/.ssh, ~/.gitconfig, ~/.npmrc, ~/.gem/credentials, ~/.bundle). A 20-40 minute random sleep precedes execution. The attacker-controlled endpoint is a bare IP on a non-standard port with no pinning, hash verification, or TLS, and the staged payload is executed from a hidden /tmp path.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/bitcoin-address-utils/MAL-2026-17586.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/bitcoin-address-utils/MAL-2026-17586.json
- https://rubygems.org/gems/bitcoin-address-utils/versions/1.0.0
- https://github.com/ossf/malicious-packages/blob/68375bfc9669351706a5a45c5039509f189d8e09/osv/malicious/rubygems/bitcoin-address-utils/MAL-2026-17586.json
- https://safedep.io/rubygems-crypto-gems-install-time-reverse-shell
- https://github.com/ossf/malicious-packages/blob/6b697dfebb1680d643ddc1cc2ee788912aa1bffa/osv/malicious/rubygems/bitcoin-address-utils/MAL-2026-17586.json
- https://github.com/advisories/GHSA-pmhw-48q6-rhv3

Compromised versions (1)

  • = 1.0.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.