MAL-2026-17608

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/rubygems/lightning-invoice-utils/MAL-2026-17608.json
JSON Data
https://api.test.osv.dev/v1/vulns/MAL-2026-17608
Published
2026-10-05T15:59:12Z
Modified
2026-10-05T16:30:11Z
Summary
Malicious code in lightning-invoice-utils (RubyGems)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (b1c7aa63129491dc29eaf240d8f4ae910733b8f6f34192279c119c3cb585c68d)

The gem declares a native extension (extconf.rb) that is auto-executed by gem install, but the shipped C stub Init_LightningInvoiceUtils is empty — the native-extension slot is a cover. extconf.rb base64-decodes an embedded Ruby payload whose destination URL is XOR-obfuscated with a 4-byte key, downloads a tarball over plain HTTP to /tmp/.w1.tgz, extracts to /tmp/.w1, and executes bash /tmp/.w1/wg_install.sh in a double-forked detached process with output redirected to /dev/null. Execution is gated by anti-analysis checks that suppress the payload in CI, on hostnames matching uvm|firecracker|sandbox|vagrant|fc[_-]?vm, on generated analyst usernames (uA\d+, sandbox|tester|analys|scanner), when running from /tmp, /var/tmp, /opt/rubygems, or /workspace/, when /proc/uptime is under 1800 seconds, and unless developer-credential paths (~/.ssh, ~/.gitconfig, ~/.npmrc, ~/.gem/credentials, ~/.bundle) are present. The advertised BOLT11 invoice-decoding functionality is not implemented in the shipped library code — the package exists to deliver the dropper to developer machines holding SSH keys and registry credentials.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-021066",
            "import_time": "2026-10-05T16:22:56.12583596Z",
            "modified_time": "2026-10-05T15:59:12Z",
            "sha256": "b1c7aa63129491dc29eaf240d8f4ae910733b8f6f34192279c119c3cb585c68d",
            "source": "amazon-inspector",
            "versions": [
                "1.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

RubyGems / lightning-invoice-utils

Package

Name
lightning-invoice-utils
Purl
pkg:gem/lightning-invoice-utils

Affected ranges

Affected versions

1.*
1.0.0

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "ext/lightning-invoice-utils/extconf.rb",
            "sha256": "44f35c300060b3092f93454fc16c802623329b9ba270f8e4a87ff2679115bf63",
            "tlsh": "0e51dc5a8b8355f54db1d0d044359412fb667b0e60689d74f3de0868bb55f2ac4f02fd"
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/rubygems/lightning-invoice-utils/MAL-2026-17608.json"