Open-source SSH tunnel VPN & Proxy client — Windows · macOS · Linux
A lightweight, minimal desktop application for creating secure SOCKS5 proxy tunnels through any SSH server using the NPVT-SSH protocol. Built with Electron and ssh2.
Grab the latest release for your platform:
| Platform | Architecture | File |
|---|---|---|
| Windows | x64 | LYNX-1.0.3-windows-x64-setup.exe |
| macOS | x64 (Intel) | LYNX-1.0.3-mac-x64.dmg |
| macOS | arm64 (M1/M2/M3/M4) | LYNX-1.0.3-mac-arm64.dmg |
| Linux | x64 | LYNX-1.0.3-linux-x64.AppImage / lynx-1.0.3-linux-x64.deb |
| Linux | arm64 (Pi 4/5) | LYNX-1.0.3-linux-arm64.AppImage / lynx-1.0.3-linux-arm64.deb |
| Linux | armv7l (Pi 2/3) | LYNX-1.0.3-linux-armv7l.AppImage / lynx-1.0.3-linux-armv7l.deb |
- NPVT-SSH Protocol — Import configs via
npvt-ssh://URI or paste JSON directly - Manual SSH Config — Add servers manually (host, port, user, password)
- SOCKS5 Proxy — Exposes
127.0.0.1:10805as a local SOCKS5 proxy - VPN Mode — System-wide proxy routing (Windows, macOS, Linux)
- TUN Mode — Full system traffic routing via virtual network adapter (macOS & Linux)
- Real-time Log — Live connection log with timestamps
- Ping Configs — Real TCP latency for each server
- Speed Test — Measures download speed through the active tunnel
- Auto-reconnect — Automatically reconnects if connection drops
- Run in Background — System tray support, stays alive when window is closed
- Dark UI — Clean black/white minimal interface
- Auto Connect — Optionally connect on app launch
- Encrypted Storage — Credentials stored encrypted on disk
# Requirements: Node.js 18+, npm
git clone https://github.com/xkmikze/lynx.git
cd lynx
npm install
# Development
npm run dev
# Build for your platform
npm run build # Windows
npm run build:mac # macOS
npm run build:linux # LinuxThe app accepts npvt-ssh:// URIs — a base64-encoded JSON config:
npvt-ssh://<base64(JSON)>
Example JSON structure:
{
"sshConfigType": "SSH-Direct",
"remarks": "My Server",
"sshHost": "1.2.3.4",
"sshPort": 22,
"sshUsername": "user",
"sshPassword": "pass",
"dnsTTMode": "UDP",
"udpgwTransparentDNS": true
}Once connected in Proxy Mode, configure your browser or system to use:
| Setting | Value |
|---|---|
| Protocol | SOCKS5 |
| Host | 127.0.0.1 |
| Port | 10805 (configurable) |
In Firefox: Preferences → Network → Manual proxy → SOCKS Host: 127.0.0.1, Port: 10805, SOCKS v5.
In Chrome: Use an extension like Proxy SwitchyOmega.
TUN mode routes all system traffic through the tunnel — not just browser traffic.
| Platform | Status | Requirements |
|---|---|---|
| macOS | ✅ Supported | Admin password on first use |
| Linux | ✅ Supported | Root or CAP_NET_ADMIN |
| Windows | 🔜 Coming Soon | Requires native driver (v1.1.0) |
# Run with sudo
sudo ./LYNX.AppImage
# Or grant capability (no sudo needed after)
sudo setcap cap_net_admin+ep LYNX.AppImagelynx/
├── src/
│ ├── main/
│ │ ├── main.js # Electron main process
│ │ ├── tunnel-manager.js # SSH + SOCKS5 tunnel
│ │ ├── tun-manager.js # TUN virtual adapter (macOS/Linux)
│ │ ├── wintun-helper/ # Windows TUN helper (coming soon)
│ │ ├── proxy-server.js # Proxy lifecycle
│ │ ├── ping-service.js # TCP latency measurement
│ │ └── speed-test.js # Download speed test
│ ├── renderer/
│ │ ├── index.html # UI layout
│ │ ├── app.js # UI logic
│ │ └── preload.js # Secure IPC bridge
│ └── shared/
│ └── config-utils.js # Config parsing & validation
├── assets/
│ ├── icons/ # App icons
│ └── wintun/ # wintun.dll (user-provided)
├── docs/ # Screenshots
├── package.json
├── .github/
│ └── workflows/
│ └── build.yml # CI/CD — builds all platforms
└── README.md
- Context Isolation — Renderer has no access to Node.js APIs directly
- Preload bridge — All IPC channels are allowlisted
- Encrypted store — Credentials encrypted at rest via
electron-store - No telemetry — Zero data sent anywhere except your SSH server
- Input validation — All config fields validated before use
- Single instance — Prevents multiple conflicting tunnels
- Windows support
- macOS support
- Linux support
- NPVT-SSH URI import
- SOCKS5 proxy mode
- System-wide VPN proxy mode
- TUN mode (macOS & Linux)
- Real-time connection log
- Ping & speed test
- Auto-reconnect on disconnect
- System tray
- TUN mode for Windows (v1.1.0)
- SSH key authentication
- Config groups / tags
- DNS over HTTPS support
- Dark/light theme toggle
- Mobile companion app
Pull requests are welcome. For major changes, open an issue first.
npm run lint # Lint
npm run pack # Test build without installerSee CONTRIBUTING.md for guidelines.
MIT © LYNX Contributors

