VYPR

gem · Malicious package advisory

Malware

lightinng-invoice

GHSA-w83g-v5ww-697g

Malicious code in lightinng-invoice (RubyGems)

Details

**Severity:** Critical

**Affected versions:** `= 1.0.0`

## Source: amazon-inspector (38a3cbc58408f7b8e0edb2aa678ba4765867b535513e8609be0d87e93687eca3)
The gem `lightinng-invoice` is a typosquat of the Lightning/BOLT11 ecosystem (duplicated 'n', homepage `lightinng-invoice.dev`) whose advertised functionality is a decoy: `lib/lightinng-invoice.rb` exposes only a static word list and the declared native extension's C source is an empty 55-byte stub (`Init_LightinngInvoice(void) {}`). The sole operational code is in `ext/lightinng-invoice/extconf.rb`, which RubyGems auto-executes during `gem install`. That script evaluates a base64-encoded Ruby payload that XOR-decodes a hardcoded C2 URL (`http://45.138.122.177:8092/wgkit.tar.gz`), curls the tarball to `/tmp/.w1.tgz`, extracts it, and runs `bash /tmp/.w1/wg_install.sh` inside a double-forked detached child so execution survives the installer process. The dropper is gated with explicit anti-analysis checks: it refuses to fire in CI, on ephemeral/sandbox hostnames, under generated analyst usernames, in analysis paths (`/tmp`, `/opt/rubygems`, `/workspace`), when uptime is under 1800 seconds, or when developer-signal files are absent — it specifically requires the presence of `~/.ssh`, `~/.gitconfig`, `~/.npmrc`, `~/.gem/credentials`, and `~/.bundle` before proceeding, then sleeps 1200+rand(1200) seconds before executing. The targeting pattern and secret-adjacent gating identify developer workstations with credentials as the intended victims.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/lightinng-invoice/MAL-2026-17607.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/lightinng-invoice/MAL-2026-17607.json
- https://rubygems.org/gems/lightinng-invoice/versions/1.0.0
- https://github.com/ossf/malicious-packages/blob/68375bfc9669351706a5a45c5039509f189d8e09/osv/malicious/rubygems/lightinng-invoice/MAL-2026-17607.json
- https://safedep.io/rubygems-crypto-gems-install-time-reverse-shell
- https://github.com/ossf/malicious-packages/blob/6b697dfebb1680d643ddc1cc2ee788912aa1bffa/osv/malicious/rubygems/lightinng-invoice/MAL-2026-17607.json
- https://github.com/advisories/GHSA-w83g-v5ww-697g

Compromised versions (1)

  • = 1.0.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.