{"id":"MAL-2026-17471","summary":"Malicious code in caoxiltts (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (23b18de964968b1d4f9333a1bcc5f247b3978f9fdc418f01f7e9a3c7bc578a62)\nThe package advertises itself as a TTS inference helper but harness.run() downloads two gzipped ELF binaries from a configurable host, verifies them against author-pinned SHA256 hashes, writes them to /tmp/.caoxiltts, chmods 0755, and executes them. The 'inference-core' binary is launched with a JSON configuration whose schema (pools[].url/user/pass/keepalive/tls, cpu.threads, mem-locked, cache-budget, autosave) is the XMRig cryptominer configuration shape, not a text-to-speech inference worker. The second binary 'edge-connector' is invoked as `access tcp --hostname \u003cedge\u003e --url 127.0.0.1:\u003cport\u003e`, matching the Cloudflare Access/cloudflared tunnel CLI shape, exposing a local port outbound through an author-controlled edge. The author-pinned hashes mean the exact bytes executed on the installer's host are chosen by the publisher, and the config/invocation pattern contradicts the package's declared TTS purpose. A supporting _report() helper additionally POSTs run_id, run state, and up to 4000 characters of exception tracebacks (which can carry local path and environment details) to https://\u003cstore\u003e/hb on the same host serving the dropped binaries.\n\n## Source: kam193 (c0d27d780e356c6ae75dedaa144f2064476e275a02f801a1d56897a3a9d1930f)\nThe package imitates real activity and instead deploys a coin miner.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-10-voxeval\n\n\nReasons (based on the campaign):\n\n\n - cryptominer\n","modified":"2026-10-04T23:45:21.529017188Z","published":"2026-10-03T19:41:50Z","database_specific":{"malicious-packages-origins":[{"source":"kam193","versions":["0.1.0","0.1.1"],"id":"pypi/2026-10-voxeval/caoxiltts","import_time":"2026-10-03T20:22:43.251097267Z","modified_time":"2026-10-03T19:41:50.061768Z","sha256":"c0d27d780e356c6ae75dedaa144f2064476e275a02f801a1d56897a3a9d1930f"},{"source":"amazon-inspector","versions":["0.1.0"],"id":"IN-MAL-2026-020901","import_time":"2026-10-04T23:40:39.993302728Z","modified_time":"2026-10-04T23:16:54Z","sha256":"819b8ae45e8f696b31aa78bf56a0a51b85b4612be1bfec9c5fbe2fb5452e4f3e"},{"versions":["0.1.1"],"id":"IN-MAL-2026-020898","import_time":"2026-10-04T23:40:39.67888865Z","modified_time":"2026-10-04T23:16:24Z","sha256":"23b18de964968b1d4f9333a1bcc5f247b3978f9fdc418f01f7e9a3c7bc578a62","source":"amazon-inspector"}]},"references":[{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/caoxiltts"},{"type":"PACKAGE","url":"https://pypi.org/project/caoxiltts/0.1.0/"},{"type":"PACKAGE","url":"https://pypi.org/project/caoxiltts/0.1.1/"}],"affected":[{"package":{"name":"caoxiltts","ecosystem":"PyPI","purl":"pkg:pypi/caoxiltts"},"versions":["0.1.0","0.1.1"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"package_integrity":[{"filename":"caoxiltts-0.1.0-py3-none-any.whl","hashes":{"blake2b_256":"73e9fb430a6a17cd7d247eaadff048336f05e012c338821a8302d1070f024a5f","md5":"066ae0db0409cb0c8b73e28e9843eb77","sha256":"52b1d16be3eaedbc1d2eb45bed547819c95da4eabebac3e564e30dafcda155ad"}}],"evidence_files":[{"sha256":"aa0409606f6902264198907cfc236fd6b80b8cf22d97b706cdc083b4d15c9089","tlsh":"9a42a5a2cd211d6383538a564963e952b70ab98757091830bdec831c2f69674c2f6fff","path":"caoxiltts/__init__.py"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/caoxiltts/MAL-2026-17471.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}