-= Per source details. Do not edit below this line.=-
The gem declares a native extension (extconf.rb) that is auto-executed by gem install, but the shipped C stub Init_LightningInvoiceUtils is empty — the native-extension slot is a cover. extconf.rb base64-decodes an embedded Ruby payload whose destination URL is XOR-obfuscated with a 4-byte key, downloads a tarball over plain HTTP to /tmp/.w1.tgz, extracts to /tmp/.w1, and executes bash /tmp/.w1/wg_install.sh in a double-forked detached process with output redirected to /dev/null. Execution is gated by anti-analysis checks that suppress the payload in CI, on hostnames matching uvm|firecracker|sandbox|vagrant|fc[_-]?vm, on generated analyst usernames (uA\d+, sandbox|tester|analys|scanner), when running from /tmp, /var/tmp, /opt/rubygems, or /workspace/, when /proc/uptime is under 1800 seconds, and unless developer-credential paths (~/.ssh, ~/.gitconfig, ~/.npmrc, ~/.gem/credentials, ~/.bundle) are present. The advertised BOLT11 invoice-decoding functionality is not implemented in the shipped library code — the package exists to deliver the dropper to developer machines holding SSH keys and registry credentials.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-021066",
"import_time": "2026-10-05T16:22:56.12583596Z",
"modified_time": "2026-10-05T15:59:12Z",
"sha256": "b1c7aa63129491dc29eaf240d8f4ae910733b8f6f34192279c119c3cb585c68d",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "ext/lightning-invoice-utils/extconf.rb",
"sha256": "44f35c300060b3092f93454fc16c802623329b9ba270f8e4a87ff2679115bf63",
"tlsh": "0e51dc5a8b8355f54db1d0d044359412fb667b0e60689d74f3de0868bb55f2ac4f02fd"
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/rubygems/lightning-invoice-utils/MAL-2026-17608.json"