MAL-2025-191872
Dashboard / Malicious Package / MAL-2025-191872
MAL-2025-191872
Summary: Malicious code in soopsocks (PyPI)
Details: Source: kam193 (adcaa2cfcfa52c7c1ed664a9389ba0bd0ddd2716ea4c475b22bcd2f62bc1ab95) The package promise creating a SOCKS proxy and report the server to a Discord webhook. And indeed appears to do so, but the attached autorun service seems to be a malware Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-09-soopsocks Reasons (based on the campaign): - malware
References: https://www.virustotal.com/gui/file/d1cb05c0e57ceb142a5e1117df4359a62df3a01f708561f4714e10e8f2af1f0d/detection, https://research.jfrog.com/post/check-your-socks-a-deep-dive-into-soopsocks-pypi/, https://bad-packages.kam193.eu/pypi/package/soopsocks
Affected packages
Package
Name: soopsocks
Purl: pkg:pypi/soopsocks
Affected ranges
Type: N/A
Events:
