Categories: Website

PyPI Users Email Phishing Attack

Read the follow-up post: Phishing Attack Follow-Up


(Ongoing, preliminary report)

PyPI has not been hacked, but users are being targeted by a phishing attackthat attempts to trick them into logging in to a fake PyPI site.

Over the past few days, users who have published projects on PyPIwith their email in package metadata may have received an email titled:

[PyPI] Email verification

from the email address noreply@pypj.org.

Note the lowercase j in the domain name,which is not the official PyPI domain, pypi.org.

This is not a security breach of PyPI itself,but rather a phishing attempt that exploits the trust users have in PyPI.

The email instructs users to follow a link to verify their email address,which leads to a phishing site that looks like PyPI but is not the official site.

The user is prompted to log in, and the requests are passed back to PyPI, which may lead to the userbelieving they have logged in to PyPI, but in reality, they have provided their credentialsto the phishing site.

PyPI Admins are looking into a few methods of handling this attack,and want to make sure users are aware of the phishing attemptwhile we investigate different options.

There is currently a banner on the PyPI homepageto warn users about this phishing attempt.

Always inspect the URL in the browser before logging in.

We are also waiting for CDN providers and name registrarsto respond to the trademark and abuse notificationswe have sent them regarding the phishing site.

If you have received this email, do not click on any links or provide any information.Instead, delete the email immediately.

If you have already clicked on the link and provided your credentials,we recommend changing your password on PyPI immediately.Inspect your account’s Security History for anything unexpected.

cmsguru

Recent Posts

How AWS Powers PyPI and the PSF

Working on infrastructure at the Python Software Foundation (PSF) as the Director of Engineering is…

1 day ago

The HTML representation of the index API is now frozen

PyPI has adopted PEP 833, which "freezes" the HTML representation of the index API, which…

1 week ago

Releases now reject new files after 14 days

The Python Package Index (PyPI) now rejects new files being uploaded to releases that are…

4 weeks ago

Planned Updates to the PyPI User Interface

Over the next few months, we will be rolling out changes to the PyPI user…

4 weeks ago

Release: Sidebar Reorganization – Part 3 – “The Switch”

Highlighting the next stage in our sidebar reorganization campaign! We are still primarily focusing on…

2 months ago

SMS Email Gateway List

Source: SMS Email Gateway ID Provider Country Email Format Notes Id Provider Country Email Address…

4 months ago

This website uses cookies.