proxy-check-iiPyPI
proxy-check-ii is a confirmed malicious PyPI package (MAL-2026-10610) that steals credentials and exfiltrates sensitive data (malicious version 0.1.0). Do not install it — remove it immediately and rotate any exposed credentials.
Malicious code in proxy-check-ii (PyPI)
What this malware does
The wheel is advertised as 'proxy-check-ii' with a one-line summary of 'packaged command for running the bundled qsshd executable' and no README, homepage, source, or author metadata. It installs a 7.7MB prebuilt Go binary at qsshd/bin/qsshd (sha256 b63ca13bc013aea83a8a9876ce1959cc07ced44e4912908e8d831f8c3b0fd72f) and a Python console script proxy-check-ii whose main() is a bare os.execv of that binary with any caller-supplied args forwarded. Strings in the binary show it links golang.org/x/crypto/ssh, github.com/hashicorp/yamux, and github.com/mydearniko/overthing/pkg/{relay,network,protocol} — an SSH/PTY server multiplexed over a yamux relay, consistent with a reverse-tunneled remote-shell overlay. The declared package name and metadata do not disclose that installing and running proxy-check-ii stands up an SSH daemon; the pure-python wheel tag also misrepresents the shipped platform-specific ELF payload. The Python wrapper performs no auditing or configuration of the binary — its runtime behavior (bind address, rendezvous endpoint, authorized keys, whether it dials out to a preset overlay) is opaque to the caller.
The embedded binary starts a relayed SSH-like server using a hardcoded authorized_key. Thanks to using a relay network, the attacked does not need to directly expose ports from the machine.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-07-proxy-check-i
Reasons (based on the campaign):
-
backdoor
-
The package contains code to execute remote commands (probably limited to a specific set) on the victim's machine.
Malicious versions
Indicators of compromise (SHA-256)
Detection & response playbook
Credential / info stealerFind it
Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for proxy-check-ii (version 0.1.0). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging proxy-check-ii across your stack and pipelines.
If you installed it — respond
proxy-check-ii is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.
Did it already run?
If proxy-check-ii was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.
How O3 protects you
O3 blocks proxy-check-ii before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.
Frequently asked questions
Campaign
References
Credits
- Amazon Inspector · finder
- Kamil Mańkowski (kam193) · reporter
Detect & block this
O3 blocks proxy-check-ii-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.