logo

Revival Hijack supply-chain attack threatens 22,000 PyPI packages

ID: 49133e6c-e954-55f0-9bdd-b1b9a496daa3

STIX ID: report--49133e6c-e954-55f0-9bdd-b1b9a496daa3

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2024-09-04

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Researchers uncovered a "Revival Hijack" attack on PyPI where threat actors register names of deleted Python packages to push malicious updates; JFrog found >22,000 packages at risk, observed an active trojanized package (pingdomv3) targeting CI/CD, and mitigated some risk by reserving popular deleted names while recommending package pinning, integrity checks, and ownership/activity monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.