caoxiltts@0.1.1
Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 8:32 AM UTC
OSV ID
MAL-2026-17471
Ecosystem
pypi
Summary
The package advertises itself as a TTS inference helper but harness.run() downloads two gzipped ELF binaries from a configurable host, verifies them against author-pinned SHA256 hashes, writes them to /tmp/.caoxiltts, chmods 0755, and executes them. The 'inference-core' binary is launched with a JSON configuration whose schema (pools[].url/user/pass/keepalive/tls, cpu.threads, mem-locked, cache-budget, autosave) is the XMRig cryptominer configuration shape, not a text-to-speech inference worker. The second binary 'edge-connector' is invoked as access tcp --hostname <edge> --url 127.0.0.1:<port>, matching the Cloudflare Access/cloudflared tunnel CLI shape, exposing a local port outbound through an author-controlled edge. The author-pinned hashes mean the exact bytes executed on the installer's host are chosen by the publisher, and the config/invocation pattern contradicts the package's declared TTS purpose. A supporting _report() helper additionally POSTs run_id, run state, and up to 4000 characters of exception tracebacks (which can carry local path and environment details) to https://<store>/hb on the same host serving the dropped binaries.
Source: amazon-inspector (23b18de964968b1d4f9333a1bcc5f247b3978f9fdc418f01f7e9a3c7bc578a62)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.