VYPR

gem · Malicious package advisory

Malware

bitcoin-rpc-lite

GHSA-xw7g-6j29-52jp

Malicious code in bitcoin-rpc-lite (RubyGems)

Details

**Severity:** Critical

**Affected versions:** `= 1.0.0`

## Source: amazon-inspector (4567a3469d6774fbe9be233375145274adf41f8e7a20521724a9a15606351044)
The gem declares ext/req_throttle_mini/extconf.rb as a native extension, but the ext/ directory ships no C/C++/Rust sources — the extension manifest exists solely to execute Ruby code during `gem install`. The script performs anti-analysis environment gating (skipping execution when CI env vars are set, hostnames match ephemeral/sandbox patterns such as uvm/firecracker/sandbox/vagrant, usernames look auto-generated, cwd is under /opt/rubygems or /tmp, system uptime is under 1800 seconds, or no developer artifacts like ~/.ssh or ~/.gem/credentials are present), then double-forks a detached background process that sleeps for a randomized 20-40 minutes before eval'ing a base64-decoded Ruby payload. The decoded payload opens a TCP socket to the hardcoded remote 45.138.12.177:8089, spawns /bin/sh via IO.popen, and bridges shell stdio over the socket in a reconnect loop, providing persistent remote shell access on the installer's host. The script closes with a trivial `require 'mkmf'; create_makefile('bitcoin_rpc_lite_native')` stub to make the extension build appear to succeed.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/bitcoin-rpc-lite/MAL-2026-17587.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/bitcoin-rpc-lite/MAL-2026-17587.json
- https://rubygems.org/gems/bitcoin-rpc-lite/versions/1.0.0
- https://github.com/ossf/malicious-packages/blob/68375bfc9669351706a5a45c5039509f189d8e09/osv/malicious/rubygems/bitcoin-rpc-lite/MAL-2026-17587.json
- https://safedep.io/rubygems-crypto-gems-install-time-reverse-shell
- https://github.com/ossf/malicious-packages/blob/6b697dfebb1680d643ddc1cc2ee788912aa1bffa/osv/malicious/rubygems/bitcoin-rpc-lite/MAL-2026-17587.json
- https://github.com/advisories/GHSA-xw7g-6j29-52jp

Compromised versions (1)

  • = 1.0.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.