{"id":"MAL-2026-17469","summary":"Malicious code in infrabench (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (97f8f2854fc15ef2f2a5d4c44b050aa9f3c87a7f5a832949390cf22ccd7882a6)\nThe package's public API harness.run(edge=\u003chost\u003e) downloads two sha256-pinned gzipped native binaries ('inference-core.bin.gz' and 'edge-conn.bin.gz') from https://\u003cedge\u003e/files/, chmods them 0755, and spawns them on the installer's host. The caller-supplied edge argument chooses only the delivery CDN; the binary contents are fixed by the author via the pinned hashes. The surrounding Python code emits a synthetic, deterministic progress trace (fabricated step/loss/tok-s lines) rather than real benchmark data, so the advertised 'evaluation harness' purpose does not match the behavior of the fetched code. The JSON configuration passed to the 'inference-core' binary — pools:[{url,user,pass:'vox',keepalive,tls}], cpu:{enabled,threads,mem-locked}, cache-budget, log-period, autosave — matches the xmrig-family mining-pool client schema rather than any inference or benchmarking worker schema, and the second binary (~19MB) is invoked as 'access tcp --hostname \u003chost\u003e --url 127.0.0.1:\u003cport\u003e', the Cloudflare cloudflared access-tunnel CLI shape used to reach a pool endpoint behind a tunnel. A _hb() routine additionally POSTs run id, state, and up to 4000 characters of exception traceback to https://\u003cedge\u003e/hb as an operator heartbeat/control-plane check-in. Installing and invoking the harness causes the installer's machine to execute author-controlled native code and donate CPU to an operator-controlled mining pool under a fake benchmarking cover story.\n\n## Source: kam193 (4abc7154004498e9054ca8ac239acd73ab86815f6029ad5d52e4c883488f4c70)\nThe package imitates real activity and instead deploys a coin miner.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-10-voxeval\n\n\nReasons (based on the campaign):\n\n\n - cryptominer\n","modified":"2026-10-04T23:45:21.374960027Z","published":"2026-10-03T16:21:40Z","database_specific":{"malicious-packages-origins":[{"versions":["0.1.0","0.1.1","0.2.0"],"id":"pypi/2026-10-voxeval/infrabench","import_time":"2026-10-03T16:51:40.851501825Z","modified_time":"2026-10-03T16:21:40.309872Z","sha256":"4abc7154004498e9054ca8ac239acd73ab86815f6029ad5d52e4c883488f4c70","source":"kam193"},{"sha256":"36dc0d39f8c45a9ebf4056b41ea346558e881f6fd826918a15c549e1754d9f36","source":"amazon-inspector","versions":["0.2.0"],"id":"IN-MAL-2026-020939","import_time":"2026-10-04T23:40:44.043292362Z","modified_time":"2026-10-04T23:23:01Z"},{"sha256":"71be58141faa0a9b081cc862370df995831d0869b8a9b3a82658752d2406aa96","source":"amazon-inspector","versions":["0.1.1"],"id":"IN-MAL-2026-020941","import_time":"2026-10-04T23:40:44.260479758Z","modified_time":"2026-10-04T23:23:23Z"},{"versions":["0.1.0"],"id":"IN-MAL-2026-020945","import_time":"2026-10-04T23:40:44.69339598Z","modified_time":"2026-10-04T23:24:01Z","sha256":"97f8f2854fc15ef2f2a5d4c44b050aa9f3c87a7f5a832949390cf22ccd7882a6","source":"amazon-inspector"}]},"references":[{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/infrabench"},{"type":"PACKAGE","url":"https://pypi.org/project/infrabench/0.2.0/"},{"type":"PACKAGE","url":"https://pypi.org/project/infrabench/0.1.1/"},{"type":"PACKAGE","url":"https://pypi.org/project/infrabench/0.1.0/"}],"affected":[{"package":{"name":"infrabench","ecosystem":"PyPI","purl":"pkg:pypi/infrabench"},"versions":["0.1.0","0.1.1","0.2.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/infrabench/MAL-2026-17469.json","indicators":{"evidence_files":[{"path":"infrabench/__init__.py","sha256":"5296464c4c5a7b7df410d3d90460491d1e4156d679057b84fe60b1e56e91c099","tlsh":"a61251f298161932c303ca5e4966e953a74e6c47ab0e6834b9fc93142fa5670c1f0fe6"}],"package_integrity":[{"filename":"infrabench-0.2.0-py3-none-any.whl","hashes":{"sha256":"e040e5c3a577a21b3c209f36d132e997752dde6726fe39d9b5945c2796bcf901","blake2b_256":"6af9c25edfe16a163806e4e42728db6001715a7be89f0936b9207a9ce1baf9a4","md5":"ca3627a2994f5002a4fd1b1716df9bcc"}}]}}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}