-= Per source details. Do not edit below this line.=-
The package imitates real activity and instead deploys a coin miner.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-10-voxeval
Reasons (based on the campaign):
{
"malicious-packages-origins": [
{
"id": "pypi/2026-10-voxeval/voxel-tts",
"import_time": "2026-10-03T04:46:19.650415945Z",
"modified_time": "2026-10-03T04:38:14.625954Z",
"sha256": "59ef2094ba4f759a0f896ff0af35b1fd19442db3cf8212a39fde46d5713c807d",
"source": "kam193",
"versions": [
"0.5.0",
"0.5.1"
]
},
{
"id": "pypi/2026-10-voxeval/voxel-tts",
"import_time": "2026-10-03T05:18:10.337930449Z",
"modified_time": "2026-10-03T04:38:14.625954Z",
"sha256": "d20f098625fe215d12359a89c03cd967a584ccc37a111c8127ce4889166af61e",
"source": "kam193",
"versions": [
"0.5.0",
"0.5.1"
]
}
]
}