Categories: Website

PyPI Users Email Phishing Attack

Read the follow-up post: Phishing Attack Follow-Up


(Ongoing, preliminary report)

PyPI has not been hacked, but users are being targeted by a phishing attackthat attempts to trick them into logging in to a fake PyPI site.

Over the past few days, users who have published projects on PyPIwith their email in package metadata may have received an email titled:

[PyPI] Email verification

from the email address noreply@pypj.org.

Note the lowercase j in the domain name,which is not the official PyPI domain, pypi.org.

This is not a security breach of PyPI itself,but rather a phishing attempt that exploits the trust users have in PyPI.

The email instructs users to follow a link to verify their email address,which leads to a phishing site that looks like PyPI but is not the official site.

The user is prompted to log in, and the requests are passed back to PyPI, which may lead to the userbelieving they have logged in to PyPI, but in reality, they have provided their credentialsto the phishing site.

PyPI Admins are looking into a few methods of handling this attack,and want to make sure users are aware of the phishing attemptwhile we investigate different options.

There is currently a banner on the PyPI homepageto warn users about this phishing attempt.

Always inspect the URL in the browser before logging in.

We are also waiting for CDN providers and name registrarsto respond to the trademark and abuse notificationswe have sent them regarding the phishing site.

If you have received this email, do not click on any links or provide any information.Instead, delete the email immediately.

If you have already clicked on the link and provided your credentials,we recommend changing your password on PyPI immediately.Inspect your account’s Security History for anything unexpected.

cmsguru

Recent Posts

New Expense Submission flow 🎉

We are pleased to announce the release of the new Expense Submission flow! 🎉We’ve done…

2 days ago

Signature Verification: How to Verify a Digital Signature Online

Digital signatures add another layer of security to your online transactions and communications. But how…

2 weeks ago

Phishing attacks with new domains likely to continue

Unfortunately the string of phishing attacks using domain-confusionand legitimate-looking emails continues. This is the same…

1 month ago

Token Exfiltration Campaign via GitHub Actions Workflows

SummaryI recently responded to an attack campaign where malicious actors injected code into GitHub Actions…

2 months ago

An Explainer Guide on Multi-Perspective Issuance Corroboration (MPIC)

Internet security is leveling up with MPIC. While your organization likely won’t need to do…

2 months ago

‘World Quantum Readiness Day’ Returns with the Latest in PQC

Sept. 10: Get actionable insights from 20+ global experts as they discuss PQC readiness assessments,…

2 months ago

This website uses cookies.