voxcpmtts3@0.1.2
Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 10:33 AM UTC
OSV ID
MAL-2026-17463
Ecosystem
pypi
Summary
The package presents itself as a text-to-speech inference library but ships two bundled binaries that implement a cryptojacking payload. voxcpmtts3/bin/voxcpm-core is XMRig (contains Monero/RandomX/CryptoNight/stratum/Hashrate/DONATE strings); harness.run() chmods it executable and spawns it via subprocess.Popen with a JSON config whose top-level key is assembled by string concatenation ("po"+"ols") to evade static analysis, carrying stratum-protocol fields (user/pass/keepalive/tls). A second bundled binary, voxcpmtts3/bin/cloudflared (~40MB), is launched with 'access tcp --hostname <edge> --url 127.0.0.1:<port>' to open a raw TCP tunnel through Cloudflare Access, hiding the real mining pool address behind a Cloudflare Access hostname and defeating destination-based blocking; a code comment acknowledges the design is to keep the traffic readable at the Cloudflare front door. In parallel, self._hb() POSTs run_id, state, Python tracebacks (up to 4000 chars) and timestamps to https://<edge>/hb through the same attacker-controlled Cloudflare Access hostname, giving the operator a per-victim telemetry channel that also leaks local filesystem paths from error traces. The 'TTS inference', 'coordinator', and 'step/loss/tok/s' terminology in code and README is cover for stratum mining pool concepts.
Source: amazon-inspector (208e19b8b5c2d9ed6169765b2b5985147d0be136e9bb5f83adac6cc691ff4aa5)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.