CLI MITM proxy that converts SOCKS4/SOCKS5 into HTTP/HTTPS/HTTP2/HTTP3 proxy with transparent TCP/UDP redirection, ARP/NDP/DNS spoofing, traffic sniffing, and packet capture. Pure Go, no libpcap.

GoHPTS CLI tool is a bridge between HTTP clients and a SOCKS5 proxy server or multiple servers (chain). It listens locally as an HTTP proxy, accepts standard HTTP
or HTTPS (via CONNECT) requests and forwards the connection through a SOCKS5 proxy. Inspired by http-proxy-to-socks and Proxychains
Possible use case: you need to connect to external API via Postman, but this API only available from some remote server. The following commands will help you to perform such a task:
Create SOCKS5 proxy server via ssh:
ssh <remote server> -D 1080 -Nf
Create HTTP-to-SOCKS5 connection with gohpts
gohpts -s :1080 -l :8080
Specify http server in proxy configuration of Postman
Proxy Chain functionality
Supports strict, dynamic, random, round_robin chains of SOCKS4/SOCKS5 proxy
Transparent proxy
Supports redirect (SO_ORIGINAL_DST) and tproxy (IP_TRANSPARENT) modes
IPv4 and IPv6 support
Operates in IPv4-only, IPv6-only or dual stack modes
TCP and UDP Transparent proxy
tproxy and tlocal (IP_TRANSPARENT) handle TCP and UDP traffic
Traffic sniffing
Proxy is able to parse HTTP headers, TLS handshake, DNS messages and more
ARP spoofing
Proxy entire subnets with ARP spoofing approach
NDP spoofing
Proxy IPv6 connections using Router/Neighbor Advertisement and RDNSS injections.
DNS spoofing
Redirect clients to arbitrary domains using DNS records manipulation
Packet Capture
Capture traffic into txt/pcap/pcapng files and analyze with Wireshark
DNS Leak Protection
DNS resolution occurs on SOCKS5 server side.
CONNECT Method Support
Supports HTTP CONNECT tunneling, enabling HTTPS and other TCP-based protocols.
HTTP2/HTTP3 Support
Supports modern HTTP/2 and HTTP/3 transport, enabling efficient multiplexed connections over TLS 1.3
Network Namespaces support
Supports custom Linux network namespaces for listening sockets and outbound connections
Trailer Headers Support
Handles HTTP trailer headers
Chunked Transfer Encoding
Handles chunked and streaming responses
SOCKS5 Authentication Support
Supports username/password authentication for SOCKS5 proxies.
HTTP Authentication Support
Supports username/password authentication for HTTP proxy server.
Lightweight and Fast
Designed with minimal overhead and efficient request handling.
Cross-Platform
Compatible with all major operating systems.
Arch Linux/CachyOS/EndeavourOS
yay -S gohpts
Or using paru:
paru -S gohpts
Download the binary for your platform from Releases page:
GOHPTS_RELEASE=v1.15.6; wget -v https://github.com/shadowy-pycoder/go-http-proxy-to-socks/releases/download/$GOHPTS_RELEASE/gohpts-$GOHPTS_RELEASE-linux-amd64.tar.gz -O gohpts && tar xvzf gohpts && mv -f gohpts-$GOHPTS_RELEASE-linux-amd64 gohpts && ./gohpts -h
Install using go install command (requires Go 1.26 or later):
CGO_ENABLED=0 go install -ldflags "-s -w" -trimpath github.com/shadowy-pycoder/go-http-proxy-to-socks/cmd/gohpts@latest
This will install the gohpts binary to your $GOPATH/bin directory.
Build from source:
git clone https://github.com/shadowy-pycoder/go-http-proxy-to-socks.git
cd go-http-proxy-to-socks
make build
./bin/gohpts
Run in docker:
docker run -it --privileged --network host -v "$PWD/gohpts.yaml:/config.yaml" shadowypycoder/gohpts:latest -f config.yaml
gohpts -h
_____ _ _ _____ _______ _____
/ ____| | | | | __ \__ __/ ____|
| | __ ___ | |__| | |__) | | | | (___
| | |_ |/ _ \| __ | ___/ | | \___ \
| |__| | (_) | | | | | | | ____) |
\_____|\___/|_| |_|_| |_| |_____/
GoHPTS: HTTP(S) Proxy to SOCKS4/SOCKS5 proxy by shadowy-pycoder
GitHub: https://github.com/shadowy-pycoder/go-http-proxy-to-socks
Codeberg: https://codeberg.org/shadowy-pycoder/go-http-proxy-to-socks
Usage: gohpts [OPTIONS]
OPTIONS:
General:
-h Show this help message and exit
-v Show version and build information
-D Run as a daemon (provide -logfile to see logs)
-I Display list of network interfaces and exit
-f Path to proxy configuration file in YAML format