logo

PyPI Blocks New File Uploads on 14-Day-Old Releases to Prevent Package Poisoning Attacks

ID: 23dc2503-18eb-5b4c-b827-d68127216b92

STIX ID: report--23dc2503-18eb-5b4c-b827-d68127216b92

Feed Name: cybersecurityNews.com

Threat Score
30/100

Date Published: 2026-07-27

Date Updated: 2026-07-27

Author: Abinaya

...
...

PyPI implemented a security change that blocks new file uploads to package releases older than 14 days to prevent attackers from silently adding malicious files to trusted package versions after compromising maintainer tokens or CI/CD workflows; the measure was motivated by past supply-chain compromises (e.g., LiteLLM and Telnyx) and was judged to have minimal impact on most maintainers after review of historical publishing patterns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.