infrabench@0.2.0
Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 7:32 AM UTC
OSV ID
MAL-2026-17469
Ecosystem
pypi
Summary
The package's public API harness.run(edge=<host>) downloads two sha256-pinned gzipped native binaries ('inference-core.bin.gz' and 'edge-conn.bin.gz') from https://<edge>/files/, chmods them 0755, and spawns them on the installer's host. The caller-supplied edge argument chooses only the delivery CDN; the binary contents are fixed by the author via the pinned hashes. The surrounding Python code emits a synthetic, deterministic progress trace (fabricated step/loss/tok-s lines) rather than real benchmark data, so the advertised 'evaluation harness' purpose does not match the behavior of the fetched code. The JSON configuration passed to the 'inference-core' binary — pools:[{url,user,pass:'vox',keepalive,tls}], cpu:{enabled,threads,mem-locked}, cache-budget, log-period, autosave — matches the xmrig-family mining-pool client schema rather than any inference or benchmarking worker schema, and the second binary (~19MB) is invoked as 'access tcp --hostname <host> --url 127.0.0.1:<port>', the Cloudflare cloudflared access-tunnel CLI shape used to reach a pool endpoint behind a tunnel. A _hb() routine additionally POSTs run id, state, and up to 4000 characters of exception traceback to https://<edge>/hb as an operator heartbeat/control-plane check-in. Installing and invoking the harness causes the installer's machine to execute author-controlled native code and donate CPU to an operator-controlled mining pool under a fake benchmarking cover story.
Source: amazon-inspector (97f8f2854fc15ef2f2a5d4c44b050aa9f3c87a7f5a832949390cf22ccd7882a6)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.