{"id":"MAL-2026-10644","title":"Malicious code in proxy-checker-j (PyPI)","summary":"Malicious code in proxy-checker-j (PyPI)","severity":"none","vendor":"proxy-checker-j","product":"proxy-checker-j","ecosystem":"pip","affected":["proxy-checker-j"],"published":"2026-07-14","updated":"2026-07-15","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/MAL-2026-10644","references":[{"url":"https://pypi.org/project/proxy-checker-j/0.1.0/"},{"url":"https://bad-packages.kam193.eu/pypi/package/proxy-checker-j"}],"tags":["osv","pip"],"ingestedAt":"2026-07-15T14:42:17.927Z","slug":"MAL-2026-10644","body":"## Overview\n\n\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (4316f8f54acc92939cdf73074666eecab7d5e680c7c4ad572ad3164671aa19dc)\nThe package is published on PyPI as `proxy-checker-j` with the summary 'packaged command for running the bundled qsshd executable', but its actual payload is a Go SSH daemon (`qsshd`) that opens persistent remote shell access to the installer's host. On execution the daemon dials out to a relay controlled through `github.com/mydearniko/overthing` and forwards inbound connections to a loopback SSH listener. The SSH listener's `PublicKeyCallback` authorizes only a single ed25519 public key embedded via `//go:embed authorized_keys`; any party holding the matching private key gets full interactive shell/PTY (`shell.Run`), arbitrary command execution (`shell.RunExec` spawning `/bin/bash`), `direct-tcpip`, and `tcpip-forward` port forwarding on the host. Persistence is established by generating a stable device identity on first run and writing it to `~/.config/.device_lock`, `/dev/shm/.device_lock`, and `/tmp/.device_lock`, pinning the host as a durable target reachable through the relay across restarts. The reverse-tunnel design lets the operator reach the host through NAT and firewalls. The advertised 'proxy checker' purpose does not match the shipped functionality; the naming is a cover story for a remote-access backdoor.\n\n## Source: kam193 (8bbbe85539f267e6bac84fa2d7653392c9235106e5f97e124f06eda25cffb38c)\nThe embedded binary starts a relayed SSH-like server using a hardcoded authorized_key. Thanks to using a relay network, the attacked does not need to directly expose ports from the machine.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-07-proxy-check-i\n\n\nReasons (based on the campaign):\n\n\n - backdoor\n\n\n - The package contains code to execute remote commands (probably limited to a specific set) on the victim's machine.\n\n\n## Affected packages\n\n- `proxy-checker-j`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}