{"id":"MAL-2026-17470","summary":"Malicious code in voxcpmruntime (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (ef6e0220a1b37d6391262539694a04726e2e5aea888941b384c4048d0a2443b2)\nThe package presents itself as a VoxCPM TTS runtime but is a binary dropper and cryptominer loader. harness.run() downloads two executables ('voxcpm-core' and 'cloudflared') from a caller-supplied edge host at https://\u003cedge\u003e/files/\u003cname\u003e, writes them under /tmp/.voxcpm-runtime/, chmods them 0o755, and spawns them. The bytes are opaque, publisher-unpinned, and verified only against SHA-256 values hardcoded in the wheel, so any host that serves the author's precomputed hashes is accepted. 'cloudflared' is launched as `access tcp --hostname \u003cedge\u003e --url 127.0.0.1:\u003cport\u003e` to tunnel a local TCP port through Cloudflare and conceal the real control-plane host. The JSON configuration written to voxcpm-run.json and passed to 'voxcpm-core' as `--config=\u003cpath\u003e` is a stratum mining-pool document (pools[{url,user,pass,keepalive,tls}], cpu.{threads,mem-locked}); the keys 'pools' and '--config=' are assembled by string concatenation ('po'+'ols', '--'+'config='+cfg_path) to evade miner-config string matching, and a _Progress class prints fabricated training-loss and tokens-per-second lines to disguise the resulting CPU load as ML inference. harness._hb() additionally POSTs run_id, state, truncated Python tracebacks and timestamps to https://\u003cedge\u003e/hb as a heartbeat channel, later routed through the Cloudflare tunnel. The name voxcpmruntime closely resembles the legitimate VoxCPM project from OpenBMB.\n\n## Source: kam193 (12f18950a276ca27a304d3053835b0102656168083e7ddf414fffb112cbe01ba)\nThe package imitates real activity and instead deploys a coin miner.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-10-voxeval\n\n\nReasons (based on the campaign):\n\n\n - cryptominer\n","modified":"2026-10-05T04:15:04.443068956Z","published":"2026-10-03T14:42:59Z","database_specific":{"malicious-packages-origins":[{"versions":["0.1.0"],"id":"pypi/2026-10-voxeval/voxcpmruntime","import_time":"2026-10-03T16:51:40.853157562Z","modified_time":"2026-10-03T14:42:59.394319Z","sha256":"12f18950a276ca27a304d3053835b0102656168083e7ddf414fffb112cbe01ba","source":"kam193"},{"sha256":"ef6e0220a1b37d6391262539694a04726e2e5aea888941b384c4048d0a2443b2","source":"amazon-inspector","versions":["0.1.0"],"id":"IN-MAL-2026-021026","import_time":"2026-10-05T03:57:39.763496373Z","modified_time":"2026-10-05T03:37:33Z"}]},"references":[{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/voxcpmruntime"},{"type":"PACKAGE","url":"https://pypi.org/project/voxcpmruntime/0.1.0/"}],"affected":[{"package":{"name":"voxcpmruntime","ecosystem":"PyPI","purl":"pkg:pypi/voxcpmruntime"},"versions":["0.1.0"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/voxcpmruntime/MAL-2026-17470.json","indicators":{"package_integrity":[{"filename":"voxcpmruntime-0.1.0-py3-none-any.whl","hashes":{"sha256":"1bfef2ae6c1de8605d1939f7429f1fc5a866d54d17fd6339cf7e8b00d44bcfed","blake2b_256":"020caf87811a1d2da2e3e162d7e2a1208dac53cb9726d925e4408edcea10e85d","md5":"2afdeb523bb7a1575efc7d34a8e3625b"}}],"evidence_files":[{"path":"voxcpmruntime/__init__.py","sha256":"3bd6e49b399a0f88bbebd6f8ac13481c4d0120c36205959953d99b1d921214c3","tlsh":"951275f2d9155932c343ca5a4a6af993a74a6c43960e5874bdfc93102f99630c2f0ff6"}]}}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}