Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

data-proxy-for-testPyPI

data-proxy-for-test is a confirmed malicious PyPI package (MAL-2026-10642) that executes malicious code on install (malicious version 0.1.1). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in data-proxy-for-test (PyPI)

MAL-2026-10642
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
pip uninstall data-proxy-for-test

What this malware does

Package distributes as data-proxy-for-test while copying the identity (author Sergey Parfenyuk, homepage/source pointing at github.com/sparfenyuk/mcp-proxy), README, and mcp_proxy module layout of the legitimate mcp-proxy project. The divergence from upstream is a mcp_proxy_logging.pth file installed into site-packages by a custom build_py in setup.py (line 18: shutil.copyfile("mcp_proxy_logging.pth", Path(self.build_lib) / "mcp_proxy_logging.pth")). Python auto-executes the .pth line import mcp_proxy.caching on every interpreter start for the affected environment — not only when the CLI is invoked. mcp_proxy/caching.py runs cache = cache_first() at module top level (line 88), which downloads files named data_proxy and data_proxy_log from https://data-proxy-for-test.oss-cn-hangzhou.aliyuncs.com/ (default base URL set at line 30) into ~/.cache/mcp-proxy/. The bytes are unpinned and unverified, fetched from a third-party Aliyun OSS bucket the upstream project does not use, and the README never mentions any cache-warmup or external download. A sibling _native() stub indicates a staging shape ready to execute the cached data_proxy artifact. Installing this package converts every subsequent Python startup into a remote-fetch from an attacker-controlled bucket and stages content for execution.

Malicious versions

1 flagged
0.1.1

Indicators of compromise (SHA-256)

2cb07f37b05b892d9785cc03fba0754ea4af3a50fab0ca6bb345ecac52b939a2

Detection & response playbook

Malicious package
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for data-proxy-for-test (version 0.1.1). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging data-proxy-for-test across your stack and pipelines.

  2. If you installed it — respond

    Remove data-proxy-for-test from your project and lockfile, then assume any secrets accessible to the build or runtime were exposed: rotate API keys, tokens, and credentials, and audit for unexpected outbound activity or persistence.

  3. Did it already run?

    If data-proxy-for-test was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks data-proxy-for-test before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. data-proxy-for-test on PyPI has been identified as a malicious package (version 0.1.1 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-010609

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks data-proxy-for-test-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the malicious outbound activity and severs the channel.

Explore

data-proxy-for-test (PyPI) malicious package — MAL-2026-10642 | O3 Security