pypi · Malicious package advisory
Malwaresoopsocks
MAL-2025-191872
Malicious code in soopsocks (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: kam193 (adcaa2cfcfa52c7c1ed664a9389ba0bd0ddd2716ea4c475b22bcd2f62bc1ab95) The package promise creating a SOCKS proxy and report the server to a Discord webhook. And indeed appears to do so, but the attached autorun service seems to be a malware --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-09-soopsocks Reasons (based on the campaign): - malware
Compromised versions (12)
- 0.2.7
- 0.2.6
- 0.2.5
- 0.2.4
- 0.2.3
- 0.2.2
- 0.2.1
- 0.2.0
- 0.1.3
- 0.1.2
- 0.1.1
- 0.1.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.