A follow-up to the previous post.
We have since learned that the campaign was orchestratedby the company that owns the inbox.ru email domain,and not by a malicious third party as we initially suspected.
Following the previous post,a representative of the parent company for inbox.ru reached outto PyPI Admins to discuss the situation.They expressed their desire to resolve the issue, and reinstate the abilityfor their users to register for PyPI accounts with email addresses from the inbox.ru domain.
They confirmed that the user account registrations on PyPI originated from an internal security team,”to prevent possible abuse of external libraries for attacks on our systems”.
They also confirmed that they have held staff meetings and have decided to abandon this practice,and develop alternate methods for detection and prevention of abuse,and have apologized for the incident.
As such, we have re-enabled the ability for users to register accountsusing the inbox.ru email domain,and to add inbox.ru email addresses to existing accounts.
We will continue to monitor the situation,and if we see any further abuse from this domain or others,we will take appropriate action to protect PyPI users and resources.
Working on infrastructure at the Python Software Foundation (PSF) as the Director of Engineering is…
PyPI has adopted PEP 833, which "freezes" the HTML representation of the index API, which…
The Python Package Index (PyPI) now rejects new files being uploaded to releases that are…
Over the next few months, we will be rolling out changes to the PyPI user…
Highlighting the next stage in our sidebar reorganization campaign! We are still primarily focusing on…
Source: SMS Email Gateway ID Provider Country Email Format Notes Id Provider Country Email Address…
This website uses cookies.