gem · Malicious package advisory
Malwarelightning-invoice-utils
GHSA-q96g-6p3p-r5cx
Malicious code in lightning-invoice-utils (RubyGems)
Details
**Severity:** Critical **Affected versions:** `= 1.0.0` ## Source: amazon-inspector (b1c7aa63129491dc29eaf240d8f4ae910733b8f6f34192279c119c3cb585c68d) The gem declares a native extension (extconf.rb) that is auto-executed by `gem install`, but the shipped C stub `Init_LightningInvoiceUtils` is empty — the native-extension slot is a cover. extconf.rb base64-decodes an embedded Ruby payload whose destination URL is XOR-obfuscated with a 4-byte key, downloads a tarball over plain HTTP to `/tmp/.w1.tgz`, extracts to `/tmp/.w1`, and executes `bash /tmp/.w1/wg_install.sh` in a double-forked detached process with output redirected to /dev/null. Execution is gated by anti-analysis checks that suppress the payload in CI, on hostnames matching `uvm|firecracker|sandbox|vagrant|fc[_-]?vm`, on generated analyst usernames (`uA\d+`, `sandbox|tester|analys|scanner`), when running from `/tmp`, `/var/tmp`, `/opt/rubygems`, or `/workspace/`, when `/proc/uptime` is under 1800 seconds, and unless developer-credential paths (`~/.ssh`, `~/.gitconfig`, `~/.npmrc`, `~/.gem/credentials`, `~/.bundle`) are present. The advertised BOLT11 invoice-decoding functionality is not implemented in the shipped library code — the package exists to deliver the dropper to developer machines holding SSH keys and registry credentials. --- Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/lightning-invoice-utils/MAL-2026-17608.json)) **References:** - https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/lightning-invoice-utils/MAL-2026-17608.json - https://rubygems.org/gems/lightning-invoice-utils/versions/1.0.0 - https://github.com/ossf/malicious-packages/blob/68375bfc9669351706a5a45c5039509f189d8e09/osv/malicious/rubygems/lightning-invoice-utils/MAL-2026-17608.json - https://safedep.io/rubygems-crypto-gems-install-time-reverse-shell - https://github.com/ossf/malicious-packages/blob/6b697dfebb1680d643ddc1cc2ee788912aa1bffa/osv/malicious/rubygems/lightning-invoice-utils/MAL-2026-17608.json - https://github.com/advisories/GHSA-q96g-6p3p-r5cx
Compromised versions (1)
- = 1.0.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.