Skip to main content

Malicious code in prosocks (PyPI)

0
Unknown
Published: 09/24/2026 (09/24/2026, 20:27:37 UTC)
Source: GCVE Database
Product: prosocks

Description

--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (cb2bf0fd5f445eed9825601f2b4497502054176d106d4fecb9eabf38312dd582) prosocks 1.0.25 enrolls the installer's host as a remote-controlled SOCKS5 exit node under a hardcoded control plane at https://kalnetz.store. setup.py's custom install command writes prosocks.bat into the Windows Startup folder (establishing boot persistence) with the command '"{python_exe}" -m prosocks https://kalnetz.store' and immediately spawns that process during `pip install`. The top-level module additionally calls _auto_launch() so that any `import prosocks` spawns a detached subprocess running the same agent. Once running, ProSocksAgent.register() queries ip-api.com and api.ipify.org for the host's public IP, generates an agent_id and proxy password, and POSTs agent_id, hostname, public IP, proxy port, and password to https://kalnetz.store/api/register, then binds a SOCKS5 server on 0.0.0.0:9050 accessible from any network the host can reach. Heartbeat and bandwidth telemetry are POSTed to /api/heartbeat and /api/bandwidth, and IP changes trigger re-registration. All requests to the panel and IP-lookup services are made with TLS verification disabled (verify=False). The combination of install-time execution, import-time execution, Windows Startup persistence, hardcoded non-first-party control plane, and an unauthenticated SOCKS5 listener on all interfaces whose credentials are handed to that control plane matches a proxyware/botnet backdoor. ## Source: kam193 (a1ca37b881f19975a8ab8b23bd5e69b51355333374385aabfc5784b69bf95545) The package automatically joins the machine to a proxy network. Depending on the version, it can happen during the package installation or when importing the module. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-09-prosocks Reasons (based on the campaign): - other - peristence-autorun - persistence

Affected software

PyPIghsa
prosocks
Affected versions
=1.0.0=1.0.1=1.0.2=1.0.3=1.0.4=1.0.5=1.0.6=1.0.7=1.0.8=1.0.9=1.0.13=1.0.14=1.0.15=1.0.16=1.0.17=1.0.18=1.0.19=1.0.20=1.0.21=1.0.22=1.0.23=1.0.25=1.0.26=1.0.27=1.0.32=1.0.28=1.0.29=1.0.30

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-17167
Osv Schema Version
1.7.4
Ecosystems
["PyPI"]

Threat ID: 6ab5fb95f7a7c5410655d199

Added to database: 09/25/2026, 04:41:57 UTC

Last updated: 09/25/2026, 04:41:57 UTC

Views: 1

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses