A malicious package named soopsocks was discovered on the Python Package Index (PyPI), masquerading as a legitimate tool for creating a SOCKS5 proxy service but actually delivering a sophisticated backdoor to Windows systems. The package was uploaded by a user with the handle "soodalpie" on September 26, 2025, and managed to attract 2,653 downloads before it was removed from the repository. Security researchers from JFrog analyzed the package and found that, in addition to its advertised SOCKS5 proxy functionality, it included a compiled Go executable named "_AUTORUN.EXE". This executable was capable of running PowerShell scripts, modifying firewall rules, and relaunching itself with elevated privileges to ensure persistence and deeper system access. The package also performed system and network reconnaissance, collecting details such as Internet Explorer security settings and the Windows installation date, which it exfiltrated to a hard-coded Discord webhook for attacker control.
The infection chain involved a Visual Basic Script ("_AUTORUN.VBS") that, in versions 0.2.5 and 0.2.6, executed a PowerShell script to download a ZIP file containing a legitimate Python binary from an external domain. This process generated a batch script to install and run the soopsocks package, which then elevated its privileges, configured firewall rules to allow UDP and TCP traffic on port 1080, and installed itself as a persistent service. The malware maintained communication with the attacker's Discord webhook, allowing for remote command and control. It also set up a scheduled task to ensure it would automatically start upon system reboot, further entrenching itself on infected machines.
The backdoor capabilities of soopsocks enabled attackers to execute arbitrary payloads, potentially granting them root or administrative access to compromised systems. The package's stealthy installation and persistence mechanisms made detection and removal more challenging for victims. The use of a popular open-source repository like PyPI for distribution increased the risk of widespread infection, as unsuspecting developers could easily incorporate the malicious package into their projects. Security researchers emphasized the importance of scrutinizing third-party packages and monitoring for unusual network activity, especially communications with known malicious endpoints such as Discord webhooks. The incident highlights ongoing threats to the software supply chain, where attackers leverage trusted platforms to distribute malware. The rapid takedown of soopsocks by PyPI administrators limited further spread, but the incident underscores the need for enhanced vetting and monitoring of open-source repositories. Organizations are advised to review their dependency lists and audit systems for signs of compromise related to the soopsocks package. The attack demonstrates the evolving tactics of threat actors in targeting developer ecosystems and exploiting automated installation processes. Defensive measures should include restricting administrative privileges, monitoring scheduled tasks, and implementing network controls to detect unauthorized outbound communications. The soopsocks incident serves as a reminder of the critical importance of supply chain security in modern software development environments.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Researchers publicly reported that soopsocks was a malicious package masquerading as a SOCKS5 proxy, and PyPI removed it from the repository. Reporting highlighted that the malware could grant elevated or root-level access and fetch additional payloads from attacker-controlled infrastructure.
Before it was taken down, the malicious soopsocks package was downloaded 2,653 times, exposing or infecting thousands of systems. Its payload chain used VBScript or a Go-based executable to launch PowerShell, alter firewall rules, open port 1080, install itself as a service, and exfiltrate host data to a Discord webhook.
A newly created account named "soodalpie" uploaded the package "soopsocks" to PyPI, advertising it as a SOCKS5 proxy tool. The package actually contained a Windows-focused backdoor and installer chain for persistence, privilege escalation, reconnaissance, and data exfiltration.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.