Development – Cycle Two Reflection and Cycle Three Overview
Reflection of Cycle Two, the second cycle of 2025, and an overview of Cycle Three. Providing insight into our product roadmap and, subsequently, the projects being worked on in our six-week cycles. Cycle Two Reflection Cycle 2 was our first time committing engineering resources to address some of theContinue Reading
Development – Cycle One Reflection and Cycle Two Overview
Here is a reflection of Cycle One, the first cycle of 2025, and an overview of Cycle Two. Providing insight into our product roadmap and, subsequently, the projects being worked on in our six-week cycles. Cycle One Reflection During Cycle One of 2025, we: Deprecated the old host reportsContinue Reading
Development – Cycle Eight Reflection and Cycle One of 2025 Overview
Here is a reflection of Cycle Eight, the last cycle of 2024, and an overview of the first Cycle of 2025 – Cycle One. Providing insight into our product roadmap and, subsequently, the projects being worked on in our six-week cycles. Cycle Eight Reflection Cycle 8 is the lastContinue Reading
Development – Cycle Seven Reflection and Cycle Eight Overview
Here is a reflection of Cycle Seven and an overview of the current; Cycle Eight. Providing insight into our product roadmap and, subsequently, the projects that are being worked on in our six-week cycles. Cycle Seven Reflection Host Efficiency We expanded the off-platform transactions tool, and fiscal hosts canContinue Reading
Cycle Seven Overview
The yearly Open Collective retreat shuffled our schedules around a bit: We used the two weeks before the retreat to tie up loose ends and take care of outstanding issues. We ended the retreat with a two day hackathon which gave the team an opportunity to propose pet projects andContinue Reading
Preventing ZIP parser confusion attacks on Python package installers
The Python Package Index is introducing new restrictions to protectPython package installers and inspectors from confusion attacks arisingfrom ZIP parser implementations. This has been done in response tothe discovery that the popular installer uv has a different extraction behaviorto many Python-based installers that use the ZIP parser implementationprovided by theContinue Reading
PyPI Phishing Attack: Incident Report
Incident Report: Phishing Attack Over the past few days, a phishing attack targeting PyPI users via email was uncovered.Our initial report was posted to raise awareness of the attack,and to provide some initial details on the attack vector. Social media posts linking to the initial report have been shared widely,PyPIContinue Reading
PyPI Users Email Phishing Attack
Read the follow-up post: Phishing Attack Follow-Up (Ongoing, preliminary report) PyPI has not been hacked, but users are being targeted by a phishing attackthat attempts to trick them into logging in to a fake PyPI site. Over the past few days, users who have published projects on PyPIwith their emailContinue Reading
inbox.ru Domain Prohibition Follow-up
A follow-up to the previous post. We have since learned that the campaign was orchestratedby the company that owns the inbox.ru email domain,and not by a malicious third party as we initially suspected. Following the previous post,a representative of the parent company for inbox.ru reached outto PyPI Admins to discussContinue Reading
Prohibiting inbox.ru email domain registrations
A recent spam campaign against PyPI has prompted an administrative action,preventing using the inbox.ru email domain.This includes new registrations as well as adding as additional addresses. The campaign created over 250 new user accounts,publishing over 1,500 new projects on PyPI,leading to end-user confusion, abuse of resources, and potential security issues.Continue Reading





