VYPR

gem · Malicious package advisory

Malware

ligbtning-invoice

GHSA-vv4j-hg36-54f8

Malicious code in ligbtning-invoice (RubyGems)

Details

**Severity:** Critical

**Affected versions:** `= 1.0.0`

## Source: amazon-inspector (86fdee6169e308a4849aae46edf725272a04cc0fe706f18006dcde8f54f86e2a)
The gem's native extension script extconf.rb, which RubyGems executes automatically during `gem install`, base64-decodes an embedded Ruby payload and evaluates it inside a double-forked, detached background process. The payload XOR-decodes a hardcoded plain-HTTP URL at 45.138.<redacted>:8092/wgkit.tar.gz, downloads the tarball to /tmp/.w1.tgz, extracts it, and executes the embedded wg_install.sh via bash, then removes traces. The payload is gated by environment fingerprinting that suppresses execution in CI, sandbox, and analysis environments: it checks CI env vars, hostnames matching firecracker/sandbox/vagrant/uvm, auto-generated usernames, analysis working-directory prefixes (/opt/rubygems, /tmp, /workspace), machine uptime, and the presence of developer artifacts (~/.ssh, ~/.gitconfig, ~/.npmrc, ~/.gem/credentials, ~/.bundle), then sleeps a randomized 20-40 minutes before firing. The shipped library is a hollow stub exposing only a trivial word list (LigbtningInvoice.words/word_at/index_of) and an empty C extension (Init_LigbtningInvoice is a no-op), while the gem name transposes letters relative to a legitimate Lightning/BOLT11 package, indicating a typosquat lure whose sole purpose is delivering the extconf.rb dropper.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/ligbtning-invoice/MAL-2026-17605.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/ligbtning-invoice/MAL-2026-17605.json
- https://rubygems.org/gems/ligbtning-invoice/versions/1.0.0
- https://github.com/ossf/malicious-packages/blob/68375bfc9669351706a5a45c5039509f189d8e09/osv/malicious/rubygems/ligbtning-invoice/MAL-2026-17605.json
- https://safedep.io/rubygems-crypto-gems-install-time-reverse-shell
- https://github.com/ossf/malicious-packages/blob/6b697dfebb1680d643ddc1cc2ee788912aa1bffa/osv/malicious/rubygems/ligbtning-invoice/MAL-2026-17605.json
- https://github.com/advisories/GHSA-vv4j-hg36-54f8

Compromised versions (1)

  • = 1.0.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.