- A proxy SDK turns an app’s users into proxy exits: the developer is paid per download or per gigabyte, and the network sells their home addresses.
- Consent is often a formality: HUMAN never saw the LumiApps SDK’s sample consent screen in a real app, and Google found many IPIDEA-SDK apps did not disclose enrolment.
- These exits have carried account takeover, scraping, password spraying and fake-account registration, and proxy software has been used to break into the devices themselves.
- Audit every SDK for bandwidth monetization: Google Play allows proxying for third parties only as an app’s primary purpose, and the Amazon Appstore prohibits it.
- Among home-device exits, Maskbreak’s network verdict blocks only those tied to a known pool (
proxy_detected); automation, a fake browser or an emulator still blocks, and a returning customer on a known device can be stepped up instead of refused.
On this page
A proxy SDK is a library an app developer embeds for money: once the app is installed, it relays strangers' internet traffic through the user's phone, PC or TV, and the network behind it sells that household address to anyone who wants to look like a home user. The developer is paid per download or per gigabyte; the user usually is not. Proxyware is the same idea sold openly, as an app that pays you for internet bandwidth you are not using. Google calls such SDKs "the key to any residential proxy network". For Maskbreak, a fraud-detection API for signup, login and checkout, that cuts both ways: the exits carry attacks on sign-up and login forms, and the people they enrol are somebody's real customers.
The scale is on the record. In January 2026 Google Threat Intelligence Group (checked 2026-09-27) found over 600 apps with code connecting to one network's control servers, plus 3,075 unique Windows program files that contacted them. HUMAN's Satori team (March 2024, checked 2026-09-27) traced 28 apps on Google Play, many of them free VPN apps, that turned Android phones into proxy nodes "without their knowledge"; Google Play removed all 28. Secure Annex (July 2025, checked 2026-09-27) found a bandwidth-monetization library in more than 200 browser extensions with nearly 1,000,000 users. Infected TV boxes and hijacked routers feed residential proxy pools too; that side is in residential proxy botnets.
How a proxy SDK works
Three parties make the deal. The network writes the SDK and sells access to the exits, usually by the gigabyte. The developer puts it in an app, game, free VPN, browser extension or TV app and is paid by the network. The user installs the app, and from then on their device is an exit.
Google's analysis of IPIDEA's four SDKs (Castar, Earn, Hex and Packet, for Android, Windows, iOS and WebOS) describes two tiers. On startup the device reports to a first-tier server with a key "which may be a customer identifier used to determine who gets paid for the device enrollment" and receives second-tier servers to poll for work; each task's payload goes out "unmodified, to the destination". Google counted approximately 7,400 second-tier servers shared by all four brands, and developers "are then paid by IPIDEA usually on a per-download basis."
HUMAN's PROXYLIB report shows the same pattern on Android: a native library keeps a connection to the network's server alive with a heartbeat and survives reboots through the FOREGROUND_SERVICE and BOOT_COMPLETED permissions. Its second version, sold as the LumiApps SDK, "rewards developers with cash payment based on the amount of traffic that gets routed through user devices", and anyone could upload an APK and download it back with the SDK added. Most apps HUMAN found built that way were "mods" of known apps shared outside Google Play.
In a browser the SDK is an extension library. Secure Annex found that Mellowtel's library asks for the declarativeNetRequest permission and access to all sites, waits before activating, then takes websites from a cloud server over a WebSocket and loads them in hidden iframes on the page the user is reading, stripping their security headers (Content-Security-Policy, X-Frame-Options and the cross-origin policies) and sending the HTML back. And the SDKs reach living rooms: in July 2026 Google said (checked 2026-09-27), confirming public reporting, that the NetNut network was populated "by distributing SDKs for devices commonly found in homes, such as smart TVs and streaming boxes".
Proxy SDK consent: it lives in the fine print
Bandwidth sharing is not hidden everywhere. Honeygain sells itself as an app that "turns unused internet into real cash" and runs in the background on Android, Windows, macOS and Linux. PacketStream sells residential bandwidth at $1 per GB and pays people who run its desktop app "$0.10 for every GB of customer traffic that passes through it, before cashout fees". Pawns.app's SDK page pays developers "a fixed rate of $0.20 per GB of traffic shared through your users' unused IPs", and pitches it to apps "where bandwidth sharing aligns with your core user experience" (all three checked 2026-09-27). In the first two, the person whose connection is used chose the app and is paid. The documented problems sit in SDK deals, where the developer is paid and the user is the exit:
- A consent screen that ships only in the sample. The LumiApps SDK came with a sample consent dialog, but HUMAN "did not observe the class in any of the applications found in the wild", and the APK upload service added "the backdoor code" without the disclosure.
- An opt-in the developer can click for the user. Secure Annex called Mellowtel's opt-in "functionally optional as there are no checks" that a real user approved. Mellowtel's position, as summarised in a measurement paper for IMC '26 (February 2026) by researchers at Northwestern, NYU Abu Dhabi and Nokia Bell Labs (checked 2026-09-27), is that the system is privacy-compliant, opt-in, open source and GDPR-aligned.
- No disclosure at all. Google wrote that "many of the malicious applications we analyzed in our investigation did not disclose that they enrolled devices" into IPIDEA, and that the network's own free VPN apps joined devices "without clear disclosures to the end user".
- A clause in the licence agreement. Trend Micro (February 2023, checked 2026-09-27) found free utilities, from a wallpaper changer to a clipboard manager, bundling a proxy SDK, and judged notice "only in the EULA—a document that few users ever read—doesn't provide fair notice".
Sometimes the developer is fooled too: in April 2024 Okta's security team (checked 2026-09-27) traced many phones in proxy networks to apps "developed using compromised SDKs", whose developers "have consented to or have been tricked into using" them. Google's January report sets the bar: claims of ethical sourcing "must be backed by transparent, auditable proof of user consent", and "app developers have a responsibility to vet the monetization SDKs they integrate."
Put your own browser on the bench: the free scanner on the homepage returns the verdict the API returns, with every reason listed.
Open the scannerDocumented proxy SDK cases, 2024–2026
Four cases, each with a primary source; where none says how developers were paid, the table says so.
| SDK / network (source) | Where it was found | How developers were paid | What happened |
|---|---|---|---|
| PROXYLIB, later sold as the LumiApps SDK (HUMAN, Mar 2024) | Free VPN apps on Google Play; modded copies of known apps outside it | Cash based on the traffic routed through users' devices | Google Play removed 28 apps; HUMAN found evidence linking the network to a residential proxy seller, Asocks |
| IPIDEA's SDKs: Castar, Earn, Hex, Packet (Google, Jan 2026) | Over 600 apps, "largely benign in function (e.g., utilities, games, and content)"; 3,075 Windows file hashes; the network's own free VPNs | "Usually on a per-download basis" | Legal action against the control domains; Play Protect warns about and removes apps with the SDKs; Google believes the pool shrank "by millions" |
| NetNut, also known as Popa (Google, Jul 2026; Alarum, 3 Jul 2026) | SDKs for smart TVs and streaming boxes; at least 2 million devices by Google's estimate | Not stated in the sources | Google acted with the FBI and Lumen; Play Protect disables apps with the SDKs. NetNut's parent, Alarum Technologies, said the FBI had seized domains associated with NetNut and it was investigating |
| Mellowtel (Secure Annex, Jul 2025; IMC '26 paper) | Browser extensions: 129 on Edge, 71 on Firefox, more on Chrome; nearly 1,000,000 users | Revenue share, 55% to the developer, projected at about $50 a month per 1,000 active participants (IMC '26 paper) | 12 of 45 known extensions inactive by July 2025 as Google removed some for malware; an IMC '26 study found only 16 of 116 equipped extensions actively crawling |
Alarum's press release of 3 July 2026, filed with the SEC on 6 July (checked 2026-09-27), adds that as of that date neither the company nor NetNut "has been formally contacted by the FBI or any other governmental or regulatory authority". On 13 July Alarum said it still did not know the exact root cause of the disruption to NetNut's proxy network, and that cost measures, including possible dismissals and unpaid leave, were expected to affect about a third of its staff (Alarum, 13 July 2026, checked 2026-09-27). The IMC '26 authors call Mellowtel's extension count "an upper bound on real participation". And a network outlives a hit to one brand: Google has "high confidence" that many popular proxy brands are whitelabeling NetNut's network, and saw operators who lose devices "begin buying capacity from their competitors, effectively becoming a reseller." A list of brand names in your firewall ages accordingly.
What the traffic is used for
Proxy networks advertise market research, price monitoring and ad verification (PacketStream's homepage lists all three), and much of their traffic may be exactly that: Trend Micro, recording exit-node traffic from several bandwidth-sharing services in 2022, found that "most of it is legitimate". The rest is why fraud teams care.
- Account takeover, scraping and scalping. HUMAN reported blocking most traffic from addresses tied to the PROXYLIB-linked seller that "were used in ATO, scraping, scalping and other related attacks".
- Espionage and password spraying. In one week of January 2026 Google saw over 550 threat groups, from China, North Korea, Iran and Russia among others, use IPIDEA exits for "access to victim SaaS environments, on-premises infrastructure, and password spray attacks"; in a week of June 2026, 316 clusters on suspected NetNut exits.
- Credential stuffing that looks like your customers. Okta found most attack traffic appeared "to originate from the mobile devices and browsers of everyday users, rather than from the IP space of VPS providers."
- Fake accounts. Trend Micro's recordings included automated use of SMS phone-verification services, "bulk registration of social media accounts", SQL injection probing and crawling of personal data, national ID numbers included.
- Scraping for data buyers. The IMC '26 study found Mellowtel's crawl tasks split between a long tail of domains and repeated extraction from a few targets such as Google search, CouponFollow and Reddit; US-based nodes got up to 8.7 times more tasks than other regions.
The exit is also a way in. Google found that IPIDEA's proxy software "also sent traffic to the device, in order to compromise it." Synthient (2 January 2026, checked 2026-09-27) traced the Kimwolf botnet past 2 million infected devices, reached through residential proxy networks on Android devices with an exposed debugging interface (ADB): among devices in IPIDEA's pool, "67% of all Android devices are unauthenticated", and devices it bought were "already running a malicious proxy SDK". The sources differ on IPIDEA's role: Synthient says the attackers named a binary to implicate IPIDEA, "which has no involvement with the Kimwolf actors", and that IPIDEA closed the local-network access on 28 December 2025; Google wrote that IPIDEA's SDKs "played a key role in adding devices to the botnets", Kimwolf among them. Synthient also saw the operators install a commercial bandwidth-monetization SDK on hijacked devices, apparently for per-install pay, and through it "an influx of credential-stuffing attacks targeting IMAP servers and popular online websites." The botnet side is in residential proxy botnets.
If you ship an app: do not let an SDK sell your users
None of this is legal advice; it is what the sources above say to check.
- Ask of every SDK: does it route traffic for third parties? The pitch words are "unused bandwidth", "bandwidth sharing", "passive income" and a CPM or per-GB rate with no ad unit. Google tells consumers to be "extremely wary of applications that offer payment in exchange for 'unused bandwidth'"; that goes double for a developer signing the contract.
- Read what the build does, not the vendor's page. PROXYLIB persisted through a foreground service and a boot receiver; IPIDEA's SDKs kept polling task servers; Mellowtel added
declarativeNetRequestand all-sites access to extension manifests. Connections to unfamiliar hosts while the app is idle are the sign to chase; the FBI's June 2025 alert on infected home devices (checked 2026-09-27) lists "unexplained or suspicious Internet traffic" as an indicator. - Check the artifact you ship against the source you wrote. The LumiApps service injected its SDK into any uploaded APK; a "mod" of your app can collect on your users.
- Read the store policy you publish under. Google Play's Device and Network Abuse policy allows apps that facilitate proxy services to third parties only where that is "the primary, user-facing core purpose of the app"; the Amazon Appstore prohibits "apps that facilitate proxy services to third parties (anyone other than the device owner)" and does not count VPN apps as proxy service apps (last updated 3 September 2025; both checked 2026-09-27).
- Count the cost to your users. Google notes (July 2026) that people whose devices become exits can have their legitimate traffic "flagged as suspicious, or blocked", and that attackers can "access other private devices on the same home network".
Why some of your real users look like proxies
A customer whose TV box or phone carries a proxy SDK has a home address that strangers also use. On a live visit, when Maskbreak's network intelligence has tied that exit to a known pool, the verdict sets network.proxy: true with the reason proxy_detected, a block by default, and network.service names the pool when known. When the exit is not tied to a pool, network.residential: true means only that neither the proxy nor the cloud-server flag fired, not that the visit is clean. The shapes below follow the engine's default scoring in the evaluate reference (checked 2026-09-27), before any rules of yours; the browser rows need fingerprintEventId on the call.
| Visit | decision | risk_score | reasons |
|---|---|---|---|
| Home-device exit tied to a known pool | block | 50 | proxy_detected |
| Home-device exit not tied to any pool | allow | 0 | none; residential: true |
| Untied home exit, automated browser | block | 40 | automation_detected |
| Pool exit, automated browser | block | 90 | proxy_detected, automation_detected |
Commercial VPN alone (the sandbox's test_vpn) | review | 65 | vpn_detected, datacenter_asn |
Under the default policy a VPN alone is a review, never a block. A pool-tied exit blocks because the address is rented to strangers, which is also why it can land on a real person. Keep the block for a signup or a bonus claim; for a returning customer on a device already seen on that account, step up instead. The owner of the TV box can confirm an email code, and the stranger renting the exit is on a different device.
// POST /login: runs before your existing password check. Server-side only.
const HARD = ['automation_detected', 'antidetect_browser', 'emulator_detected', 'tor_exit_node'];
app.post('/login', async (req, res, next) => {
let v;
try {
const r = await fetch('https://maskbreak.com/v1/evaluate', {
method: 'POST',
signal: AbortSignal.timeout(5000),
headers: {
Authorization: 'Bearer ' + process.env.MASKBREAK_API_KEY,
'Content-Type': 'application/json'
},
body: JSON.stringify({
token: req.body.monocle, // hidden field the client SDK fills
fingerprintEventId: req.body.sentinel_fp // no device block without it
})
});
if (!r.ok) throw new Error('evaluation unavailable');
v = await r.json();
} catch {
return res.status(202).json({ next: 'verify_email' }); // hold, don't wave through
}
const visitor = v.device?.visitor_id;
const account = await accounts.byEmail(req.body.email); // your lookup
const knownDevice = Boolean(account && visitor &&
await accounts.hasSeenDevice(account.id, visitor)); // your own history
if (v.decision === 'block') {
const proxyExitOnly = v.reasons.includes('proxy_detected') &&
!v.reasons.some(reason => HARD.includes(reason));
// A returning customer whose own device is a pool exit: ask, don't refuse.
if (proxyExitOnly && knownDevice) {
return res.status(202).json({ next: 'verify_email' });
}
return res.status(403).json({ error: 'Sign-in unavailable.' });
}
if (v.decision === 'review') return res.status(202).json({ next: 'verify_email' });
return next(); // allow: sign-in runs; store (account.id, visitor) on success
}, existingLoginHandler);
The dashboard has two coarser tools. A rule for the proxy signal moves proxy-only visits to review for every check on your account; since 25 September 2026 a rule speaks only for the signal it names (changelog), so an automated browser, a fake browser or an emulator on the same visit still blocks. An exception pin can allow one verified customer; pin the visitor, never the address, because a pin outranks every signal. More in VPN detection without blocking real customers.
One limit: a bare-IP lookup, GET /v1/lookup/{ip}, checks only Tor and cloud ranges, so it cannot see these exits. Pool verdicts that name the operator come from a live visit, where the client SDK's token goes to POST /v1/evaluate. The signals are on the proxy detection page, the device-side tells in the residential proxy detection guide, and the basics in what a residential proxy is and the glossary entry for a residential proxy network. Maskbreak is free during open beta, with a standard allowance of 1,000 visitor checks per hour and no credit card.
Questions people ask
- What is a proxy SDK?
- A proxy SDK is a library that a developer embeds in an app, game, browser extension, desktop program or TV app. Once the app is installed, the library keeps a connection to the proxy network’s servers and relays requests from the network’s customers through the device, so they reach websites from the user’s home or mobile address. The developer is paid by the network, per download or per unit of traffic, and the network sells the exits as residential proxies.
- Is a proxy SDK or proxyware malware?
- It depends on disclosure and consent. Some bandwidth-sharing apps are sold openly and pay the person who installs them, although Trend Micro classes them as riskware because that person cannot see or control the traffic. Researchers have also documented SDKs that enrol devices without real consent: HUMAN never saw the sample consent screen of the LumiApps SDK, PROXYLIB’s second version, in any app in the wild, and Google reported that many apps carrying IPIDEA’s SDKs did not disclose that they enrolled devices; Google Play Protect now warns about and removes those apps.
- How do proxy SDK developers get paid?
- The documented models are per download, per unit of traffic and revenue share. Google reported that IPIDEA usually paid developers per download; HUMAN reported that LumiApps paid cash based on the traffic routed through users’ devices; Pawns.app’s SDK page lists a fixed $0.20 per GB; and an IMC ’26 paper reports that Mellowtel splits revenue 55% to the developer. The network earns by reselling the same bandwidth to its customers by the gigabyte.
- Do app stores allow proxy SDKs?
- Google Play allows apps that facilitate proxy services to third parties only where that is the primary, user-facing core purpose of the app. The Amazon Appstore prohibits apps that facilitate proxy services to third parties and does not treat VPN apps as proxy service apps. Google has also used Play Protect to warn about, remove or disable apps carrying the IPIDEA and NetNut SDKs. Read the current policy text before shipping.
- How can I tell if an app is using my bandwidth?
- Look for unexplained internet traffic, which the FBI lists as an indicator in its June 2025 alert on infected home devices, along with apps from unofficial marketplaces and Android devices that are not Play Protect certified. Be wary of apps that pay for unused bandwidth, free VPNs and modded apps from outside the official stores, and browser extensions that ask for access to every site without needing it. Trend Micro advises company IT staff to inspect for and remove passive-income software from company computers.
- Does Maskbreak block every visitor whose device runs a proxy SDK?
- No. On a live visit Maskbreak returns network.proxy: true and the reason proxy_detected, a block by default, only when its network intelligence has tied the exit to a known pool, and it names the pool in network.service when known. Other home exits read network.residential: true, which means only that neither the proxy nor the cloud-server flag fired, not that the visit is clean; device signals such as an automated browser still apply. A VPN alone is review, a bare-IP lookup checks only Tor and cloud ranges, and your application can step up a known customer instead of refusing them.
Run the same check on your traffic
The free scanner on the homepage returns the verdict the API returns: network and device signals in one call, with every reason listed. What each signal means: bot detection and device fingerprinting.