PyPI urges users to reset credentials after new phishing attacks
ID: 008aa481-d86a-5e47-90da-dd69ca80c3ab
STIX ID: report--008aa481-d86a-5e47-90da-dd69ca80c3ab
Feed Name: Bleeping Computer
The Python Software Foundation warns of an active phishing campaign using fake PyPI websites (e.g., pypi-mirror.org and previously pypj.org) that request credential verification to steal maintainer accounts; stolen credentials could enable attackers to modify or publish malicious Python packages. The advisory urges affected users to change passwords, inspect account security history, enable phishing-resistant 2FA (hardware keys), avoid clicking links in emails, and report malicious domains and suspicious activity to PyPI.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
