Website

Sponsored

Phishing attacks with new domains likely to continue

Unfortunately the string of phishing attacks using domain-confusionand legitimate-looking emails continues. This is the same attack PyPI saw a few…

1 month ago

Token Exfiltration Campaign via GitHub Actions Workflows

SummaryI recently responded to an attack campaign where malicious actors injected code into GitHub Actions workflows attempting to steal PyPI…

1 month ago

Preventing Domain Resurrection Attacks

SummaryPyPI now checks for expired domains to prevent domain resurrection attacks,a type of supply-chain attack where someone buys an expired…

2 months ago

PyPI now serves project status markers in API responses

PyPI now serves project status markers in its standardindex APIs. This allows downstream consumers (like Python package installers andindex mirrors)…

3 months ago

Preventing ZIP parser confusion attacks on Python package installers

The Python Package Index is introducing new restrictions to protectPython package installers and inspectors from confusion attacks arisingfrom ZIP parser…

3 months ago

PyPI Phishing Attack: Incident Report

Incident Report: Phishing AttackOver the past few days, a phishing attack targeting PyPI users via email was uncovered.Our initial report…

3 months ago

PyPI Users Email Phishing Attack

Read the follow-up post: Phishing Attack Follow-Up(Ongoing, preliminary report)PyPI has not been hacked, but users are being targeted by a…

3 months ago

inbox.ru Domain Prohibition Follow-up

A follow-up to the previous post.We have since learned that the campaign was orchestratedby the company that owns the inbox.ru…

3 months ago

Prohibiting inbox.ru email domain registrations

A recent spam campaign against PyPI has prompted an administrative action,preventing using the inbox.ru email domain.This includes new registrations as…

3 months ago

Incident Report: Organizations Team privileges

On April 14, 2025 security@pypi.org was notified of a potential security concernrelating to privileges granted to a PyPI User via…

3 months ago

This website uses cookies.