-= Per source details. Do not edit below this line.=-
The gem 'bitcion-ruby' is a one-edit typosquat of 'bitcoin-ruby'. The library has no real functionality (lib/ exposes only a hardcoded 48-word list; ext/bitcion-ruby/bitcion-ruby.c is an empty Init stub). The native extension's ext/bitcion-ruby/extconf.rb runs at gem install time and, before invoking create_makefile, base64-decodes and evals a Ruby payload. The payload performs sandbox/CI/analysis-environment fingerprinting (checks for ~/.ssh, ~/.gitconfig, ~/.gem/credentials, ~/.bundle, ~/.npmrc, requires uptime > 30 minutes, excludes CI environment variables and hostnames matching patterns like 'uvm', 'firecracker', 'sandbox', rejects generated-looking usernames and /tmp or /workspace working directories). On a real developer machine, it forks a detached child that sleeps 20-40 minutes, then curls a tarball to /tmp/.w1.tgz from a URL reconstructed by XOR-decoding a hardcoded hex string with the 4-byte key 'usv\x9a' (overridable via the WG_KIT_URL env var), extracts it, and executes wg_install.sh via bash. The combination of typosquat identity, empty cover functionality, two-layer obfuscation (base64 eval + XOR-encoded URL), environment fingerprinting to evade analysis sandboxes, randomized long sleep, detached forked execution, and fetch-and-exec of a remote shell script constitutes a full install-time remote code execution against developer machines that install the gem.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-021059",
"import_time": "2026-10-05T16:22:55.521128359Z",
"modified_time": "2026-10-05T15:58:13Z",
"sha256": "27214f874c511d94a54d727b98ceb9feaec97d4b916794a9993c430cd215fc70",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "ext/bitcion-ruby/extconf.rb",
"sha256": "d887dfb17b7b9a79d3817d2f32e805e27f797e39d335e332b69051117585982a",
"tlsh": "2251ca568b8395f54db1d0d044359412fb667b0d6068a864f3de0868bb5af2ac4f02fd"
},
{
"path": "metadata.yaml",
"sha256": "016b697d059867b7de4189ba7e134198db203db4d798a11d1cec7ae0cdef5fd2",
"tlsh": "c221df806fc1f476f485e2e95c127a03b3b3e9e8be57380059cba08563cd15e3e97128"
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/rubygems/bitcion-ruby/MAL-2026-17584.json"