Logo
pypi

houdus@1.0.1

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 2:33 PM UTC

Malicious

OSV ID

MAL-2026-15933

Ecosystem

pypi

Summary

The package advertises random-number helpers but its generator.py side-loads houdus/assests/ssd.wav as Python via importlib.util.spec_from_file_location + exec_module the first time any of its RNG APIs (pick_int, select_item, etc.) is called. The.wav file is Python source shipped under a mismatched extension and contains: multi-signal VM/sandbox detection (WMI, CPUID hypervisor bit, MAC/BIOS/registry checks), RAM checks, 30-second sleeps, and a base64-encoded URL decoding to https://lamabdefs-sesaonion-ho.netlify.app/wobble.py. On non-sandbox Windows hosts the loader silently installs pycryptodome, downloads wobble.py into %APPDATA%\Microsoft\Windows\Start Menu\Programs\<python>\wobble.wav, launches it with pythonw.exe using CREATE_NO_WINDOW, and self-deletes. The Start Menu Programs path and headless pythonw launch provide persistence and stealth. Extension disguise, base64 URL obfuscation, and anti-analysis gating rule out any benign interpretation; nothing in the package's stated RNG purpose requires remote code execution.

Source: amazon-inspector (6f1c6df3b6cf8e44eceecfcd1aa44ee0301e8921b0c5294560c0031c0b17b6e6)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.