-= Per source details. Do not edit below this line.=-
The package's top-level init.py imports starts.py, which is a single-line loader that reverses a ~100KB string literal, base64-decodes it, marshal.loads the result into a code object, and exec()s it. All actual functionality is concealed behind reversal + base64 + marshal bytecode obfuscation, with an empty README and empty PKG-INFO description. The obfuscated code object runs automatically on import proxycer, so any behavior it contains (credential access, outbound network, filesystem writes, persistence) executes on the installer's host without source visibility.
The provided functionality hides code that exfiltrates files to a remote location.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-09-asti
Reasons (based on the campaign):
files-exfiltration
action-hidden-in-lib-usage
target:android
{
"iocs": {
"ips": [
"35.170.187.220"
]
},
"malicious-packages-origins": [
{
"id": "pypi/2025-02-pxz/proxycer",
"import_time": "2026-09-05T08:21:09.28703412Z",
"modified_time": "2026-09-05T07:39:50.331077Z",
"sha256": "5f66d65c62bde80f94cc75ce1b15bf00995f3dcb1434fb94dd4d452236f9e478",
"source": "kam193",
"versions": [
"0.1.0"
]
},
{
"id": "pypi/2026-09-asti/proxycer",
"import_time": "2026-09-05T12:23:37.470728151Z",
"modified_time": "2026-09-05T11:57:41.704885Z",
"sha256": "c7f54d8a442ae6b7c359629af5db210aafade4776e03f44895e67923bd464e29",
"source": "kam193",
"versions": [
"0.1.0"
]
},
{
"id": "IN-MAL-2026-019650",
"import_time": "2026-09-06T14:38:06.068513136Z",
"modified_time": "2026-09-06T14:28:50Z",
"sha256": "2286dac5be0a9e8cc2e7b1ff92253d4b09beb0c43d5e795b9b9ea1391e6f8764",
"source": "amazon-inspector",
"versions": [
"0.1.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "proxycer/starts.py",
"sha256": "49980877cf5fa4c71df6a2e9d969197884b5e6c96a9f740275838e74b1bf46a4",
"tlsh": "2ea39e0d8d67fdb514d97c9ec5dfa172877850240923b82b6ec7bc3b582b818a63b161"
}
],
"package_integrity": [
{
"filename": "proxycer-0.1.0-py3-none-any.whl",
"hashes": {
"blake2b_256": "6b08ccb93682e342a04625d69e615bcd21d488062e80dbd336cbccfea65bd5ed",
"md5": "3ffb918f9ddec7676b3b2be126da6a1c",
"sha256": "fd48e6018fd8c54b75b0e5fe87857d049fe2d6a03ccfbf2ea04ae6c194bcc0ef"
}
},
{
"filename": "proxycer-0.1.0.tar.gz",
"hashes": {
"blake2b_256": "b3be7cfab70db1016634ed2941d6c6b69279b5a95c135186afc047509e355b44",
"md5": "19fc95c76071210cf63032c59bccaedb",
"sha256": "af81662d9e272ac13466be0f557903d3c2d40bbe68e0df068b449bc312de249e"
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/proxycer/MAL-2026-15935.json"