voxel-tts@0.5.1
Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 10:33 AM UTC
OSV ID
MAL-2026-17461
Ecosystem
pypi
Summary
The package advertises text-to-speech inference but contains no model, audio, or inference code. Importing voxel_tts loads voxel_tts/harness.py, which instantiates a module-level Harness(); on run() it chmods and executes a bundled ~8MB ELF at voxel_tts/bin/voxel-core. The ELF is invoked with a JSON configuration matching the XMRig-family CPU mining schema (pools/user/pass/keepalive/tls, cpu.threads, cpu.mem-locked, cache-budget), and the pool-protocol key 'pools' is split across string concatenation to evade static scanners. The pool destination is reconstructed at runtime by base64-decoding two fragments ('MTg1LjE5NA==', 'MTc3LjI0OQ==') and joining them with '.', yielding 185.194.177.249:443. A 40MB cloudflared binary is also bundled at voxel_tts/bin/cloudflared and launched as 'cloudflared access tcp --hostname <host> --url 127.0.0.1:<port>' so that outbound mining traffic egresses through Cloudflare Access to an author-controlled hostname, hiding the real pool IP from host network logs; in-code comments acknowledge this is to avoid 'direct egress to the coordinator's own address'. In parallel, a _Progress helper emits synthetic 'model | step N/250000 loss=... tok/s=... lr=6e-5 ep=...' lines once per minute as a cover story to make the workload appear to be ML training. Net effect: installing and using this package runs a cryptominer on the installer's CPU, monetizing their compute for the author, while actively evading detection via destination obfuscation, tunneled egress, and a fabricated training-progress UI.
Source: amazon-inspector (31bcd85c4464339b45ec445d1c402ecbc97ab4b50b71738d1fc3873c88f9cff5)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.