Logo
pypi

voxeval@0.4.5

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 8:32 AM UTC

Malicious

OSV ID

MAL-2026-17457

Ecosystem

pypi

Summary

The package advertises itself as a TTS evaluation harness but ships two large bundled binaries and executes them on the installer's host. voxeval/bin/voxtts-core is an ~8MB ELF launched with an XMRig-shaped configuration (pools, donate-level, print-time, huge-pages, cpu.threads, user=run_id, pass="vox") pointing at a hardcoded Monero pool at 185.194.177.249:443. The pool host is split into two base64 chunks (MTg1LjE5NA==, MTc3LjI0OQ==) and reassembled at runtime, and configuration keys are string-concatenated ("po"+"ools", "--"+"config=") to defeat literal keyword scans. A second bundled binary, a ~40MB cloudflared, is invoked as cloudflared access tcp --hostname <edge> --url 127.0.0.1:<port> --no-autoupdate to proxy the miner's egress through Cloudflare's edge and evade DNS/IP-based blocking of the pool. A _Progress helper fabricates fake training-progress lines (step N/250000 loss=... tok/s=...) so the miner's output resembles ML training in notebook logs. The dropper chmods the core binary to 0o755 and spawns it via Popen. Installing or invoking voxeval causes sustained CPU consumption on the installer's host for the benefit of the attacker's mining wallet, with egress deliberately obscured.

Source: amazon-inspector (4b542a4c53b4c08e104eebfade64c8e91c8d731c4a9bd298e48a258117c5b1bb)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.