VYPR

gem · Malicious package advisory

Malware

lightning-invoice-utils

GHSA-q96g-6p3p-r5cx

Malicious code in lightning-invoice-utils (RubyGems)

Details

**Severity:** Critical

**Affected versions:** `= 1.0.0`

## Source: amazon-inspector (b1c7aa63129491dc29eaf240d8f4ae910733b8f6f34192279c119c3cb585c68d)
The gem declares a native extension (extconf.rb) that is auto-executed by `gem install`, but the shipped C stub `Init_LightningInvoiceUtils` is empty — the native-extension slot is a cover. extconf.rb base64-decodes an embedded Ruby payload whose destination URL is XOR-obfuscated with a 4-byte key, downloads a tarball over plain HTTP to `/tmp/.w1.tgz`, extracts to `/tmp/.w1`, and executes `bash /tmp/.w1/wg_install.sh` in a double-forked detached process with output redirected to /dev/null. Execution is gated by anti-analysis checks that suppress the payload in CI, on hostnames matching `uvm|firecracker|sandbox|vagrant|fc[_-]?vm`, on generated analyst usernames (`uA\d+`, `sandbox|tester|analys|scanner`), when running from `/tmp`, `/var/tmp`, `/opt/rubygems`, or `/workspace/`, when `/proc/uptime` is under 1800 seconds, and unless developer-credential paths (`~/.ssh`, `~/.gitconfig`, `~/.npmrc`, `~/.gem/credentials`, `~/.bundle`) are present. The advertised BOLT11 invoice-decoding functionality is not implemented in the shipped library code — the package exists to deliver the dropper to developer machines holding SSH keys and registry credentials.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/lightning-invoice-utils/MAL-2026-17608.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/lightning-invoice-utils/MAL-2026-17608.json
- https://rubygems.org/gems/lightning-invoice-utils/versions/1.0.0
- https://github.com/ossf/malicious-packages/blob/68375bfc9669351706a5a45c5039509f189d8e09/osv/malicious/rubygems/lightning-invoice-utils/MAL-2026-17608.json
- https://safedep.io/rubygems-crypto-gems-install-time-reverse-shell
- https://github.com/ossf/malicious-packages/blob/6b697dfebb1680d643ddc1cc2ee788912aa1bffa/osv/malicious/rubygems/lightning-invoice-utils/MAL-2026-17608.json
- https://github.com/advisories/GHSA-q96g-6p3p-r5cx

Compromised versions (1)

  • = 1.0.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.