MAL-2025-191872

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/soopsocks/MAL-2025-191872.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-191872
Published
2025-09-26T16:20:15Z
Modified
2025-12-31T02:51:04.893977Z
Summary
Malicious code in soopsocks (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: kam193 (adcaa2cfcfa52c7c1ed664a9389ba0bd0ddd2716ea4c475b22bcd2f62bc1ab95)

The package promise creating a SOCKS proxy and report the server to a Discord webhook. And indeed appears to do so, but the attached autorun service seems to be a malware


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2025-09-soopsocks

Reasons (based on the campaign):

  • malware
Database specific
{
    "malicious-packages-origins": [
        {
            "import_time": "2025-12-02T22:30:55.601059851Z",
            "modified_time": "2025-09-26T16:26:52.468777Z",
            "sha256": "6b1d078aff71031e0681d4377e92d0e9d398f3f18d1fc92ab6f97f94a93697d5",
            "source": "kam193",
            "versions": [
                "0.2.7",
                "0.2.6",
                "0.2.5",
                "0.2.4",
                "0.2.3",
                "0.2.2",
                "0.2.1",
                "0.2.0",
                "0.1.3",
                "0.1.2",
                "0.1.1",
                "0.1.0",
                "0.2.7"
            ],
            "id": "pypi/2025-09-soopsocks/soopsocks"
        },
        {
            "import_time": "2025-12-02T23:07:18.640582329Z",
            "modified_time": "2025-09-26T16:26:52.468777Z",
            "sha256": "adcaa2cfcfa52c7c1ed664a9389ba0bd0ddd2716ea4c475b22bcd2f62bc1ab95",
            "source": "kam193",
            "versions": [
                "0.2.7",
                "0.2.6",
                "0.2.5",
                "0.2.4",
                "0.2.3",
                "0.2.2",
                "0.2.1",
                "0.2.0",
                "0.1.3",
                "0.1.2",
                "0.1.1",
                "0.1.0",
                "0.2.7"
            ],
            "id": "pypi/2025-09-soopsocks/soopsocks"
        },
        {
            "import_time": "2025-12-30T22:39:04.180662186Z",
            "modified_time": "2025-09-26T16:26:52.468777Z",
            "sha256": "ca432b15dd310c0563790ddbffb84582f20b388625f6860669a89d0522f0b4f1",
            "source": "kam193",
            "versions": [
                "0.1.0",
                "0.1.1",
                "0.1.2",
                "0.1.3",
                "0.2.0",
                "0.2.1",
                "0.2.2",
                "0.2.3",
                "0.2.4",
                "0.2.5",
                "0.2.6",
                "0.2.7",
                "0.2.7"
            ],
            "id": "pypi/2025-09-soopsocks/soopsocks"
        }
    ],
    "iocs": {
        "domains": [
            "soop.space"
        ],
        "urls": [
            "https://discord.com/api/webhooks/1418298773330985154/_I7EzXpGMundYt8jCvlDdzi9INsBkBq7NSDM74iV0Y_flSzQZ5LxYP0lZtXFzHCkRtKR",
            "http://install.soop.space:6969/download/py/pythonportable.zip",
            "http://install.soop.space"
        ]
    }
}
References
Credits

Affected packages

PyPI / soopsocks

Package

Affected ranges

Affected versions

0.*
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/soopsocks/MAL-2025-191872.json"