HomeSecurityMalicious PyPI soopsocks package infected 2,653 systems

Malicious PyPI package soopsocks infected 2,653 systems

Cybersecurity researchers have identified a malicious package in the Python Package Index (PyPI) repository that claims to offer the ability to create a SOCKS5 proxy service , while also providing a hidden backdoor function to install additional payloads on Windows systems.

See also: New Phishing Attack Targets PyPI Administrators

PyPI

The deceptive package, called soopsocks, attracted a total of 2,653 downloads before being removed. It was first uploaded by a user named “soodalpie” on September 26, 2025, the same day the account was created.

The executable (“_AUTORUN.EXE”) is a compiled Go file that, in addition to implementing SOCKS5 as advertised, is also designed to run PowerShell scripts, configure firewall rules, and reboot with elevated privileges. It also performs basic system and network identification, including Internet Explorer security settings and Windows installation date, and outputs the information to a pre-defined Discord webhook.

“_AUTORUN.VBS,” the Visual Basic Script launched by the Python package in versions 0.2.5 and 0.2.6, is also capable of executing a PowerShell script, which then downloads a ZIP file containing the legitimate Python binary from an external domain (“install.soop[.]space:6969”) and creates a batch script configured to install the package using the “pip install” command and execute it.

See also: AI Villager tool reaches 11,000 downloads on PyPI

Malicious PyPI package soopsocks infected 2,653 systems

The PowerShell script then calls the batch script, causing the Python package to execute, which, in turn, elevates its privileges to run with administrator privileges (if it isn't already), configures firewall rules to allow UDP and TCP communication over port 1080, installs itself as a service, maintains communication with a Discord webhook, and sets up persistence on the host system using a scheduled task to ensure it starts automatically on system reboot.

The revelation comes as npm package maintainers have raised concerns about the lack of native 2FA workflows for CI/CD, support for self-hosted workflows for trusted publishing, and token management following sweeping changes introduced by GitHub in response to a growing wave of attacks on the software supply chain, Socket.

Earlier this week, GitHub said it would soon revoke all legacy tokens for npm publishers and that all tokens with granular access for npm would have a default expiration of seven days (down from 30 days) and a maximum expiration of 90 days, previously unlimited.

See also: PyPI: Malicious packages exploit dependency for supply chain attacks

Malicious PyPI package soopsocks infected 2,653 systems

This also comes as the software supply chain security company has released a free tool called Socket Firewall that blocks malicious packages upon installation across the npm, Python, and Rust ecosystem, giving developers the ability to protect their environments from potential threats.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS