Logo
pypi

voxcpmui3@0.1.0

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 7:32 AM UTC

Malicious

OSV ID

MAL-2026-17464

Ecosystem

pypi

Summary

The package presents itself as a text-to-speech inference harness but contains no TTS code. On calling the exported Harness.run, the module chmods +x and spawns a bundled ~8MB native binary at bin/voxcpm-core with a JSON config whose fields match a stratum mining pool (url/user/pass/keepalive/tls under a dict key, cpu.threads, cpu.mem-locked, cache-budget). The miner's pool-list key is assembled by string concatenation ("po"+"ols") rather than written as a literal, an evasion of static scanners that search for the literal key. A ~40MB cloudflared binary is also bundled and invoked as cloudflared access tcp --hostname <edge> --url 127.0.0.1:<port>, so the native core connects to loopback while traffic is tunneled through a Cloudflare-Access-protected hostname chosen by the caller — concealing the mining pool destination from network egress monitoring. The harness emits fabricated step/loss/tok-s progress lines generated from a seeded random.Random to maintain the training cover story. The combined effect is that installers who follow the README donate CPU cycles to the author's mining pool while the destination is obscured behind a tunneling binary.

Source: amazon-inspector (e9db4ea82be2cd2e2d4d7eb40236b22a9ccd0e0414cad836b98ca63468c4071e)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.