voxcpmruntime@0.1.0
Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 5:32 AM UTC
OSV ID
MAL-2026-17470
Ecosystem
pypi
Summary
The package presents itself as a VoxCPM TTS runtime but is a binary dropper and cryptominer loader. harness.run() downloads two executables ('voxcpm-core' and 'cloudflared') from a caller-supplied edge host at https://<edge>/files/<name>, writes them under /tmp/.voxcpm-runtime/, chmods them 0o755, and spawns them. The bytes are opaque, publisher-unpinned, and verified only against SHA-256 values hardcoded in the wheel, so any host that serves the author's precomputed hashes is accepted. 'cloudflared' is launched as access tcp --hostname <edge> --url 127.0.0.1:<port> to tunnel a local TCP port through Cloudflare and conceal the real control-plane host. The JSON configuration written to voxcpm-run.json and passed to 'voxcpm-core' as --config=<path> is a stratum mining-pool document (pools[{url,user,pass,keepalive,tls}], cpu.{threads,mem-locked}); the keys 'pools' and '--config=' are assembled by string concatenation ('po'+'ols', '--'+'config='+cfg_path) to evade miner-config string matching, and a _Progress class prints fabricated training-loss and tokens-per-second lines to disguise the resulting CPU load as ML inference. harness._hb() additionally POSTs run_id, state, truncated Python tracebacks and timestamps to https://<edge>/hb as a heartbeat channel, later routed through the Cloudflare tunnel. The name voxcpmruntime closely resembles the legitimate VoxCPM project from OpenBMB.
Source: amazon-inspector (ef6e0220a1b37d6391262539694a04726e2e5aea888941b384c4048d0a2443b2)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.