'Revival Hijack' on PyPI Disguises Malware With Legitimate File Names
ID: 3ccdfc63-6f9a-54da-b747-c377f3e99e64
STIX ID: report--3ccdfc63-6f9a-54da-b747-c377f3e99e64
Feed Name: Dark Reading
Threat Score
JFrog researchers detail the "Revival Hijack" supply-chain technique on PyPI in which attackers re-register removed package names to push malicious updates; their research found roughly 120,000 reusable names (≈22,000 high-risk packages), demonstrated the attack by publishing benign replacements that nonetheless accumulated ~200,000 downloads, and recommended prohibiting reuse of removed package names and hardening CI/CD workflows.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
