{"id":"MAL-2026-10610","summary":"Malicious code in proxy-check-ii (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (a736498f3f882a4ba79f793dc893883db41d8cb5a74ecfe0c66dace9cc477a20)\nThe wheel is advertised as 'proxy-check-ii' with a one-line summary of 'packaged command for running the bundled qsshd executable' and no README, homepage, source, or author metadata. It installs a 7.7MB prebuilt Go binary at qsshd/bin/qsshd (sha256 b63ca13bc013aea83a8a9876ce1959cc07ced44e4912908e8d831f8c3b0fd72f) and a Python console script proxy-check-ii whose main() is a bare os.execv of that binary with any caller-supplied args forwarded. Strings in the binary show it links golang.org/x/crypto/ssh, github.com/hashicorp/yamux, and github.com/mydearniko/overthing/pkg/{relay,network,protocol} — an SSH/PTY server multiplexed over a yamux relay, consistent with a reverse-tunneled remote-shell overlay. The declared package name and metadata do not disclose that installing and running proxy-check-ii stands up an SSH daemon; the pure-python wheel tag also misrepresents the shipped platform-specific ELF payload. The Python wrapper performs no auditing or configuration of the binary — its runtime behavior (bind address, rendezvous endpoint, authorized keys, whether it dials out to a preset overlay) is opaque to the caller.\n\n## Source: kam193 (8a222abeb680e48d3cffbdeb7f0d6cba713b023d825b2c42c7a849b36b2fe0a5)\nThe embedded binary starts a relayed SSH-like server using a hardcoded authorized_key. Thanks to using a relay network, the attacked does not need to directly expose ports from the machine.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-07-proxy-check-i\n\n\nReasons (based on the campaign):\n\n\n - backdoor\n\n\n - The package contains code to execute remote commands (probably limited to a specific set) on the victim's machine.\n","modified":"2026-07-15T05:20:20.153826994Z","published":"2026-07-14T17:07:54Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-07-14T17:07:55.382887Z","versions":["0.1.0"],"source":"kam193","sha256":"8a222abeb680e48d3cffbdeb7f0d6cba713b023d825b2c42c7a849b36b2fe0a5","import_time":"2026-07-14T18:28:30.436093172Z","id":"pypi/2026-07-proxy-check-i/proxy-check-ii"},{"modified_time":"2026-07-14T21:24:15Z","versions":["0.1.0"],"source":"amazon-inspector","sha256":"a736498f3f882a4ba79f793dc893883db41d8cb5a74ecfe0c66dace9cc477a20","import_time":"2026-07-14T21:49:52.858601453Z","id":"IN-MAL-2026-010568"}]},"references":[{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/proxy-check-ii"},{"type":"PACKAGE","url":"https://pypi.org/project/proxy-check-ii/0.1.0/"}],"affected":[{"package":{"name":"proxy-check-ii","ecosystem":"PyPI","purl":"pkg:pypi/proxy-check-ii"},"versions":["0.1.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/proxy-check-ii/MAL-2026-10610.json","cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"package_integrity":[{"hashes":{"blake2b_256":"11bfbabde3b5358e6234734f32c279fc505cd883e4fff790130d1fa2aa11e537","md5":"9073606141e11e5a0c1c936bfe2d10b1","sha256":"51de744e1104acbaf1be76b84d5d57703a20ea56f101f1a333f2d311d5e41eef"},"filename":"proxy_check_ii-0.1.0-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl"}],"evidence_files":[{"path":"proxy_check_ii-0.1.0.data/purelib/qsshd/launcher.py","sha256":"6b64a3efa390eb5f181d70a6604744c0ffead9d91957e6a2bdd5133eb6080f5c","tlsh":"0621c04ad9e21c63d5a5e398d7023c2b036664b33575182abd1f91601f4e0b680b5958"},{"sha256":"a28fa63ed45b973e855cf25adc27e35bc0218ae1ac11ec30283fa636e26cf3d2","tlsh":"0ed02b91639071b0b099cad5010c5a61459ad24256ca15d6c9e21fca098922847db030","path":"proxy_check_ii-0.1.0.dist-info/METADATA"}]}}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}