{"id":"MAL-2026-10690","title":"Malicious code in qwen-asr-pvt (PyPI)","summary":"Malicious code in qwen-asr-pvt (PyPI)","severity":"none","vendor":"qwen-asr-pvt","product":"qwen-asr-pvt","ecosystem":"pip","affected":["qwen-asr-pvt"],"published":"2026-07-15","updated":"2026-07-15","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/MAL-2026-10690","references":[{"url":"https://pypi.org/project/qwen-asr-pvt/0.0.6/"}],"tags":["osv","pip"],"ingestedAt":"2026-07-16T18:59:41.903Z","slug":"MAL-2026-10690","body":"## Overview\n\n\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (68e8b2f6db0443a648cdf03348c8dd9351568469f84b8d61022f1ed1da2a330e)\nThe package's pyproject.toml declares an unpinned runtime dependency on `transformers4576`, a lookalike of the widely used HuggingFace `transformers` library. Every internal import that would normally reference `transformers` has been rewritten to `transformers4576` (e.g., `from transformers4576 import AutoConfig, AutoModel, AutoProcessor` reachable from __init__.py), so `pip install qwen-asr-pvt` forces pip to resolve and install the attacker-controlled `transformers4576` from PyPI. Whatever code is published under that name executes at install/import time on the installer's machine. The lure is reinforced by publisher impersonation: the package name `qwen-asr-pvt` (a `-pvt` suffix on the real `qwen-asr`), the `Alibaba Qwen Team` author metadata, and the homepage pointing at `https://github.com/Qwen/Qwen3-ASR` mimic the official Qwen3-ASR project, while the shipped source is copied from that upstream with import statements rewritten to the typosquat name. Together these signals form a dependency-confusion dropper: the flagged package is the lure, and the harm arrives through the attacker-controlled transitive.\n\n\n## Affected packages\n\n- `qwen-asr-pvt`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}