OSV ID
MAL-2026-16410
Ecosystem
pypi
Summary
The pip install of auclean 0.4.2 runs a custom setup.py build_py command that chmod 0755's and executes a 1.8MB bundled Rust ELF binary auclean/_auclean_native with --init, output suppressed. The package's stated purpose is pure-Python audio DSP (numpy/wave/soundfile) and no C/Rust source is shipped, so the binary is opaque and its execution is unrelated to any advertised functionality. Strings inside the binary reveal a full HTTPS client stack (ureq 2.12.1, rustls 0.23.45), DNS/socket primitives, hardcoded references to container-secret and system paths (/var/run/secrets, /etc/resolv.conf, /dev/shm, /tmp/_ac), and process-manipulation primitives (posix_spawn, setuid, setgid, chroot, execvp) — none of which are consistent with audio normalization, and all of which are consistent with harvesting Kubernetes/CI service-account tokens and other credentials from build/CI environments. The same install-time path also calls auclean._bootstrap.fetch_assets, which downloads a manifest and referenced files from https://auclean-cdn.alcoholpepsi.workers.dev/dl/auclean/0.4.2 — an anonymous free workers.dev subdomain under an unrelated handle with no tie to the stated publisher; the manifest determines which files are written under ~/.cache/auclean/ at install time, so the fetched content is attacker-controlled. The README advertises a from auclean import AudioPipeline; pipeline.run() API that does not exist in the shipped Python source, indicating the Python surface is a cover story for the install-time payload delivered by the native binary and the CDN channel.
Source: amazon-inspector (535d1083af63653f3cc6befeffe23a6fd97cea9b183b95eac92779a5abcdcd9d)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.