---
id: MAL-2026-17167
title: Malicious code in prosocks (PyPI)
summary: Malicious code in prosocks (PyPI)
severity: critical
exploited: true
vendor: prosocks
product: prosocks
ecosystem: pip
affected:
  - prosocks
published: '2026-09-24'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T03:00:06.522127273Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/MAL-2026-17167'
references:
  - url: 'https://bad-packages.kam193.eu/pypi/package/prosocks'
  - url: 'https://pypi.org/project/prosocks/1.0.22/'
  - url: 'https://pypi.org/project/prosocks/1.0.13/'
  - url: 'https://pypi.org/project/prosocks/1.0.32/'
  - url: 'https://pypi.org/project/prosocks/1.0.18/'
  - url: 'https://pypi.org/project/prosocks/1.0.23/'
  - url: 'https://pypi.org/project/prosocks/1.0.19/'
  - url: 'https://pypi.org/project/prosocks/1.0.25/'
  - url: 'https://pypi.org/project/prosocks/1.0.20/'
  - url: 'https://pypi.org/project/prosocks/1.0.17/'
  - url: 'https://pypi.org/project/prosocks/1.0.28/'
  - url: 'https://pypi.org/project/prosocks/1.0.26/'
  - url: 'https://pypi.org/project/prosocks/1.0.29/'
  - url: 'https://pypi.org/project/prosocks/1.0.21/'
  - url: 'https://pypi.org/project/prosocks/1.0.30/'
  - url: 'https://pypi.org/project/prosocks/1.0.27/'
tags:
  - osv
  - pip
  - malware
ingestedAt: '2026-09-25T07:17:06.724Z'
---

## Overview


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (cb2bf0fd5f445eed9825601f2b4497502054176d106d4fecb9eabf38312dd582)
prosocks 1.0.25 enrolls the installer's host as a remote-controlled SOCKS5 exit node under a hardcoded control plane at https://kalnetz.store. setup.py's custom install command writes prosocks.bat into the Windows Startup folder (establishing boot persistence) with the command '"{python_exe}" -m prosocks https://kalnetz.store' and immediately spawns that process during `pip install`. The top-level module additionally calls _auto_launch() so that any `import prosocks` spawns a detached subprocess running the same agent. Once running, ProSocksAgent.register() queries ip-api.com and api.ipify.org for the host's public IP, generates an agent_id and proxy password, and POSTs agent_id, hostname, public IP, proxy port, and password to https://kalnetz.store/api/register, then binds a SOCKS5 server on 0.0.0.0:9050 accessible from any network the host can reach. Heartbeat and bandwidth telemetry are POSTed to /api/heartbeat and /api/bandwidth, and IP changes trigger re-registration. All requests to the panel and IP-lookup services are made with TLS verification disabled (verify=False). The combination of install-time execution, import-time execution, Windows Startup persistence, hardcoded non-first-party control plane, and an unauthenticated SOCKS5 listener on all interfaces whose credentials are handed to that control plane matches a proxyware/botnet backdoor.

## Source: kam193 (a1ca37b881f19975a8ab8b23bd5e69b51355333374385aabfc5784b69bf95545)
The package automatically joins the machine to a proxy network. Depending on the version, it can happen during the package installation or when importing the module.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-09-prosocks


Reasons (based on the campaign):


 - other


 - peristence-autorun


 - persistence


## Affected packages

- `prosocks`

## Remediation

Refer to the advisory for the patched release.
