-= Per source details. Do not edit below this line.=-
The gem declares a native extension (ext/bitciin/extconf.rb) that runs during gem install. The shipped C source (ext/bitciin/bitciin.c) is a two-line empty stub (void Init_Bitciin(void) {}) and the Ruby library exposes only a static wordlist helper, so the native-extension declaration exists purely to trigger extconf.rb. extconf.rb applies a sandbox-evasion gate (checks for CI environment variables, hostname/username/cwd regexes, uptime > 1800s, and presence of ~/.ssh, ~/.gitconfig, ~/.gem/credentials, ~/.bundle, and /.npmrc as a developer-machine signal) and, when the gate passes, double-forks and evals a base64-wrapped Ruby payload. The payload reconstructs a C2 URL by XORing a hex blob with the 4-byte key /.gem/credentials, ~/.npmrc), consistent with a credential-targeted stage-2.usv\x9a (with env-var override WG_KIT_URL), sleeps 20-40 minutes, then curls a tarball to /tmp/.w1.tgz and executes bash /tmp/.w1/wg_install.sh. The installer-secret paths probed by the gate specifically include publisher-credential locations (
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-021058",
"import_time": "2026-10-05T16:22:55.428472327Z",
"modified_time": "2026-10-05T15:58:03Z",
"sha256": "73144cb471499af4467e7c8c2a6da34013285179444e101290faa7ec9fda0a19",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "ext/bitciin/extconf.rb",
"sha256": "977d0764ae375bd6a338c2dd9a3e55ea732a20b19fb9b0ec035171bb8f39f68e",
"tlsh": "6851db568b8395f54db1d0d044355412fb667b0d6068ac64f3de086cbb5af2ac4f02fd"
},
{
"path": "ext/bitciin/bitciin.c",
"sha256": "3ea6f0ef00d7fe7e8436de537736458949461e26f1cc4904956a49d523a9351a"
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/rubygems/bitciin/MAL-2026-17582.json"