Malicious code in socks5901 (PyPI)
The PyPI package socks5901 contained malicious code that exfiltrates files from /sdcard/ during import and communicates via Telegram bot. The package was identified and cataloged by the OpenSSF malicious-packages project.
- Disclosed
- Last updated
- Blast radius
- Unknown; depends on adoption of malicious versions
- Ecosystems
- Attack vectors
- Affected entities
- socks5901
The PyPI package socks5901 was found to contain malicious code with clear intent to steal information. Upon import, the package exfiltrates all files from the /sdcard/ directory, typically associated with Android devices.\n\nThe malicious behavior includes communication via a Telegram bot for command and control. This campaign was tracked as 2026-08-socks5901 and identified by the OpenSSF's malicious-packages project.\n\nThe package was credited to kam193 and has been documented in the OpenSSF malicious-packages repository with identifier MAL-2026-14100.
Indicators of compromise
- Packages
- socks5901
Remediation
- Remove socks5901 from all environments immediately
- Audit systems that imported socks5901 for signs of file exfiltration or unauthorized Telegram bot communication
- Review /sdcard/ access logs and file transfer history on affected Android systems
- Monitor for indicators of compromise related to the identified Telegram bot
- Use dependency scanning tools to identify any projects that depend on socks5901
Sources
- GitHub Advisory GHSA-3rcw-hq5f-gvrg · GitHub Advisory Database
Cite this entry
"Malicious code in socks5901 (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 18, 2026; last updated August 18, 2026. https://supplychainattack.org/incident/malicious-code-in-socks5901-pypi-1cyey4
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
Malicious code in scrambleeeer (PyPI)
The PyPI package scrambleeeer contains malicious code that establishes a reverse shell to a hardcoded location, allowing remote command execution on affected systems. The package was identified as part of a malicious campaign and has been documented by the OpenSSF.
2026 08 ScrambleeerPyPICompromised package - containedcritical
Malicious code in reqcrypts (PyPI)
The reqcrypts package on PyPI contains malicious code that implements a hidden backdoor. The package masquerades as an HTTP request library but secretly monitors responses for specific fields and executes their content without user knowledge.
2026 08 ReqcryptPyPICompromised packageMalicious commit - containedcritical
Malicious code in boto4 (PyPI)
A malicious package named boto4 was published to PyPI containing embedded executable code capable of cryptomining, remote command execution, persistence, data exfiltration, and worm-style propagation controlled via Telegram bot. The package was identified and attributed to the 2026-08-boto4 campaign by the OpenSSF.
2026 08 Boto4PyPICompromised package - containedcritical
Malicious code in scrambleeer (PyPI)
The scrambleeer package on PyPI contained malicious code that establishes a reverse shell to a hardcoded location, enabling arbitrary command execution on affected systems. The malicious package was identified and cataloged by the OpenSSF malicious-packages project.
2026 08 ScrambleeerPyPICompromised package