Skip to content
supplychainattack.orgSupply chain attack incident catalog
resolvedcritical

Malicious code in socks5901 (PyPI)

The PyPI package socks5901 contained malicious code that exfiltrates files from /sdcard/ during import and communicates via Telegram bot. The package was identified and cataloged by the OpenSSF malicious-packages project.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Unknown; depends on adoption of malicious versions
Ecosystems
Attack vectors
Affected entities
  • socks5901

The PyPI package socks5901 was found to contain malicious code with clear intent to steal information. Upon import, the package exfiltrates all files from the /sdcard/ directory, typically associated with Android devices.\n\nThe malicious behavior includes communication via a Telegram bot for command and control. This campaign was tracked as 2026-08-socks5901 and identified by the OpenSSF's malicious-packages project.\n\nThe package was credited to kam193 and has been documented in the OpenSSF malicious-packages repository with identifier MAL-2026-14100.

Indicators of compromise

Packages
  • socks5901

Remediation

  • Remove socks5901 from all environments immediately
  • Audit systems that imported socks5901 for signs of file exfiltration or unauthorized Telegram bot communication
  • Review /sdcard/ access logs and file transfer history on affected Android systems
  • Monitor for indicators of compromise related to the identified Telegram bot
  • Use dependency scanning tools to identify any projects that depend on socks5901

Sources

  1. GitHub Advisory GHSA-3rcw-hq5f-gvrg · GitHub Advisory Database

Cite this entry

"Malicious code in socks5901 (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 18, 2026; last updated August 18, 2026. https://supplychainattack.org/incident/malicious-code-in-socks5901-pypi-1cyey4

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedcritical

    Malicious code in scrambleeeer (PyPI)

    The PyPI package scrambleeeer contains malicious code that establishes a reverse shell to a hardcoded location, allowing remote command execution on affected systems. The package was identified as part of a malicious campaign and has been documented by the OpenSSF.

    2026 08 ScrambleeerPyPICompromised package
  2. containedcritical

    Malicious code in reqcrypts (PyPI)

    The reqcrypts package on PyPI contains malicious code that implements a hidden backdoor. The package masquerades as an HTTP request library but secretly monitors responses for specific fields and executes their content without user knowledge.

    2026 08 ReqcryptPyPICompromised packageMalicious commit
  3. containedcritical

    Malicious code in boto4 (PyPI)

    A malicious package named boto4 was published to PyPI containing embedded executable code capable of cryptomining, remote command execution, persistence, data exfiltration, and worm-style propagation controlled via Telegram bot. The package was identified and attributed to the 2026-08-boto4 campaign by the OpenSSF.

    2026 08 Boto4PyPICompromised package
  4. containedcritical

    Malicious code in scrambleeer (PyPI)

    The scrambleeer package on PyPI contained malicious code that establishes a reverse shell to a hardcoded location, enabling arbitrary command execution on affected systems. The malicious package was identified and cataloged by the OpenSSF malicious-packages project.

    2026 08 ScrambleeerPyPICompromised package