logo

Hackers target Python devs in phishing attacks using fake PyPI site

ID: 8e8d8ac6-b660-54ae-97e1-4be67b611990

STIX ID: report--8e8d8ac6-b660-54ae-97e1-4be67b611990

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2025-07-30

Date Updated: 2026-07-19

Author: Sergiu Gatlan

...
...

The Python Software Foundation warned of an active phishing campaign in which threat actors send emails titled '[PyPI] Email verification' linking to a cloned site (pypj.org) that prompts developers to sign in; credentials entered are harvested and may be used to inject malware into existing PyPI packages or publish malicious packages. PyPI has added a homepage banner, urged users to delete the emails and change passwords if compromised, and is working with registrars and CDNs to disrupt the phishing site.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.