MAL-2026-17167

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/prosocks/MAL-2026-17167.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17167
Published
2026-09-24T20:27:37Z
Modified
2026-09-25T03:00:06Z
Summary
Malicious code in prosocks (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (cb2bf0fd5f445eed9825601f2b4497502054176d106d4fecb9eabf38312dd582)

prosocks 1.0.25 enrolls the installer's host as a remote-controlled SOCKS5 exit node under a hardcoded control plane at https://kalnetz.store. setup.py's custom install command writes prosocks.bat into the Windows Startup folder (establishing boot persistence) with the command '"{python_exe}" -m prosocks https://kalnetz.store' and immediately spawns that process during pip install. The top-level module additionally calls _auto_launch() so that any import prosocks spawns a detached subprocess running the same agent. Once running, ProSocksAgent.register() queries ip-api.com and api.ipify.org for the host's public IP, generates an agent_id and proxy password, and POSTs agent_id, hostname, public IP, proxy port, and password to https://kalnetz.store/api/register, then binds a SOCKS5 server on 0.0.0.0:9050 accessible from any network the host can reach. Heartbeat and bandwidth telemetry are POSTed to /api/heartbeat and /api/bandwidth, and IP changes trigger re-registration. All requests to the panel and IP-lookup services are made with TLS verification disabled (verify=False). The combination of install-time execution, import-time execution, Windows Startup persistence, hardcoded non-first-party control plane, and an unauthenticated SOCKS5 listener on all interfaces whose credentials are handed to that control plane matches a proxyware/botnet backdoor.

Source: kam193 (a1ca37b881f19975a8ab8b23bd5e69b51355333374385aabfc5784b69bf95545)

The package automatically joins the machine to a proxy network. Depending on the version, it can happen during the package installation or when importing the module.


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-09-prosocks

Reasons (based on the campaign):

  • other

  • peristence-autorun

  • persistence

Database specific
{
    "iocs":  {
        "domains":  [
            "kalnetz.store"
        ]
    },
    "malicious-packages-origins":  [
        {
            "id":  "pypi/2026-09-prosocks/prosocks",
            "import_time":  "2026-09-24T21:17:51.820938555Z",
            "modified_time":  "2026-09-24T20:27:37.240742Z",
            "sha256":  "a1ca37b881f19975a8ab8b23bd5e69b51355333374385aabfc5784b69bf95545",
            "source":  "kam193",
            "versions":  [
                "1.0.0",
                "1.0.1",
                "1.0.2",
                "1.0.3",
                "1.0.4",
                "1.0.5",
                "1.0.6",
                "1.0.7",
                "1.0.8",
                "1.0.9",
                "1.0.13",
                "1.0.14",
                "1.0.15",
                "1.0.16",
                "1.0.17",
                "1.0.18",
                "1.0.19",
                "1.0.20",
                "1.0.21",
                "1.0.22",
                "1.0.23",
                "1.0.25",
                "1.0.26",
                "1.0.27"
            ]
        },
        {
            "id":  "IN-MAL-2026-020530",
            "import_time":  "2026-09-25T02:45:28.491373497Z",
            "modified_time":  "2026-09-25T02:38:41Z",
            "sha256":  "76e0eae860e10e88d75ea8b07c167738b690efd073a617896ea5ad6a0792c755",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.22"
            ]
        },
        {
            "id":  "IN-MAL-2026-020539",
            "import_time":  "2026-09-25T02:45:28.779169994Z",
            "modified_time":  "2026-09-25T02:40:07Z",
            "sha256":  "8f29f98ed08ae514405c11088ba947720af42c40dfe1c27366150cd5bac7f347",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.13"
            ]
        },
        {
            "id":  "IN-MAL-2026-020547",
            "import_time":  "2026-09-25T02:45:29.000691993Z",
            "modified_time":  "2026-09-25T02:41:14Z",
            "sha256":  "aa6a62b2bc3bb7b72b4be1eabd9a18855746a708a75e60e2ee5b69eb1a7d428d",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.32"
            ]
        },
        {
            "id":  "IN-MAL-2026-020540",
            "import_time":  "2026-09-25T02:45:28.803991112Z",
            "modified_time":  "2026-09-25T02:40:15Z",
            "sha256":  "bddc16df6cd97016b03613b0145b94bd73d832dfd439af5b5d2fd123a7aa1aa2",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.18"
            ]
        },
        {
            "id":  "IN-MAL-2026-020534",
            "import_time":  "2026-09-25T02:45:28.642912922Z",
            "modified_time":  "2026-09-25T02:39:21Z",
            "sha256":  "000f63ce0bd21488923efbf77dfcc4cbba6f35e870cff786b508f775a53b5196",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.23"
            ]
        },
        {
            "id":  "IN-MAL-2026-020535",
            "import_time":  "2026-09-25T02:45:28.668915916Z",
            "modified_time":  "2026-09-25T02:39:29Z",
            "sha256":  "37b5a9fa3464dc2a2b48c44d832f66309a50cc91529e52dc4dee6bfe1b4aa69f",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.19"
            ]
        },
        {
            "id":  "IN-MAL-2026-020528",
            "import_time":  "2026-09-25T02:45:28.407650176Z",
            "modified_time":  "2026-09-25T02:38:20Z",
            "sha256":  "cb2bf0fd5f445eed9825601f2b4497502054176d106d4fecb9eabf38312dd582",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.25"
            ]
        },
        {
            "id":  "IN-MAL-2026-020536",
            "import_time":  "2026-09-25T02:45:28.697878755Z",
            "modified_time":  "2026-09-25T02:39:40Z",
            "sha256":  "409e4363b70e5d2e1194b484c55842d42d6feabd4219604a8bf28d6d5386690a",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.20"
            ]
        },
        {
            "id":  "IN-MAL-2026-020537",
            "import_time":  "2026-09-25T02:45:28.721905139Z",
            "modified_time":  "2026-09-25T02:39:47Z",
            "sha256":  "870b800018606622dc818d3f1bea56a620e37255f2f0c0d6c90e08fdeec9ed35",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.17"
            ]
        },
        {
            "id":  "IN-MAL-2026-020548",
            "import_time":  "2026-09-25T02:45:29.025826713Z",
            "modified_time":  "2026-09-25T02:41:24Z",
            "sha256":  "caa7416059850559330a9960c6b769b1f60fc84ece462205638a7b88599a7eb8",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.28"
            ]
        },
        {
            "id":  "IN-MAL-2026-020527",
            "import_time":  "2026-09-25T02:45:28.384228105Z",
            "modified_time":  "2026-09-25T02:38:11Z",
            "sha256":  "d49a320dd58a4870230ae0ca5064f62cc944ba54e0b4826942544ae72f5addd7",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.26"
            ]
        },
        {
            "id":  "IN-MAL-2026-020544",
            "import_time":  "2026-09-25T02:45:28.915488658Z",
            "modified_time":  "2026-09-25T02:40:49Z",
            "sha256":  "23054a22019d252872e2388241e5b3a2316d375f3339b7d29e91509d906c4ba7",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.29"
            ]
        },
        {
            "id":  "IN-MAL-2026-020533",
            "import_time":  "2026-09-25T02:45:28.617646638Z",
            "modified_time":  "2026-09-25T02:39:13Z",
            "sha256":  "45fadb3326809bdbd1ffe08b9406d56368185ee3e3e4a0b1bdde76016ecd9a7d",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.21"
            ]
        },
        {
            "id":  "IN-MAL-2026-020545",
            "import_time":  "2026-09-25T02:45:28.943705042Z",
            "modified_time":  "2026-09-25T02:40:58Z",
            "sha256":  "ca84a489288e0d475797752133d56030bdd562f28d97500e3584d5cb54a74148",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.30"
            ]
        },
        {
            "id":  "IN-MAL-2026-020529",
            "import_time":  "2026-09-25T02:45:28.4655852Z",
            "modified_time":  "2026-09-25T02:38:31Z",
            "sha256":  "367e20039ff925711e169e6c72923dd980abe616b8b8ec85eed30d4110942b4f",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.27"
            ]
        }
    ]
}
References
Credits

Affected packages

PyPI / prosocks

Package

Affected ranges

Affected versions

1.*
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.20
1.0.21
1.0.22
1.0.23
1.0.25
1.0.26
1.0.27
1.0.28
1.0.29
1.0.30
1.0.32

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    },
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    },
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    },
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    },
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    },
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    },
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    },
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    },
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    },
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    },
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    },
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    },
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    },
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    },
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "prosocks.py",
            "sha256":  "36e4b6471122c9d7adf077850e052721b68b19e2e8c4a29446f84bc383fad0dc",
            "tlsh":  "51624345e4154ca6c28b851ac423b6573b9eb9070a4f643cb8fce3886f9413561f9ef6"
        },
        {
            "path":  "setup.py",
            "sha256":  "1e1f7b6e7c501565e08841ff785e48587698b4355bd8883473ca26545e08ee5c",
            "tlsh":  "24212167c87f653445c283a1585f29261beb82134f08e8e478ed52640fcf03e846c76b"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "prosocks-1.0.22-py3-none-any.whl",
            "hashes":  {
                "blake2b_256":  "1429615116396984a5e55879c1e85c3da7d018d604bf132cf7e000ffca0ac712",
                "md5":  "969239bdda594fef437704e5e716a113",
                "sha256":  "3803ebd4d544b4f5a72408edfaa03fb586fdaacaa7cf6dfa37777ebf6b397520"
            }
        },
        {
            "filename":  "prosocks-1.0.22.tar.gz",
            "hashes":  {
                "blake2b_256":  "cf40d567a0e466c45e56aa9b8e003ff959cc6734691bd6e4a4ccbefd4716dd53",
                "md5":  "276fa254d49e89bcee722564b084a8ee",
                "sha256":  "3bd6f1e0cf535577b8185a51761f1b09fca1dd89b5b64a2a92dc2133b119e9c6"
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/prosocks/MAL-2026-17167.json"