pypi
Malicious socks5901 @1.0.0
Vulnerability report · Last retrieved from osv.dev August 18, 2026 at 1:42 AM UTC
OSV ID
MAL-2026-14100
Ecosystem
pypi
Summary
During import, package exfiltrates all files from "/sdcard/" --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-08-socks5901 Reasons (based on the campaign): - files-exfiltration - uses-telegram-bot - target:android
Source: kam193 (e6184fc1c33621ffa99f06b96ac94f05944bc3c7b431243e50ede0bb396e7dd3)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.