PyPI tackles domain resurrection: Why it matters — and what’s missing
ID: 25fc885a-9415-54c3-8887-0d9bbc7e4f0f
STIX ID: report--25fc885a-9415-54c3-8887-0d9bbc7e4f0f
Feed Name: ReversingLabs Blog
PyPI will automatically invalidate maintainer emails from expired domains to block domain-resurrection account takeovers, reducing supply-chain risk from hijacked packages; the move, already de-verifying ~1,800 addresses with periodic status checks, is a low-friction control that other repos (npm, RubyGems, Maven Central) are urged to adopt. The piece outlines attackers’ favorite package-repo TTPs (account takeover, dependency confusion, typosquatting), notes persistent gaps (account recovery, orphaned projects, weak defaults, opaque ownership transfers), and calls for stronger baselines such as MFA, integrity safeguards, cryptographic signing, and provenance frameworks (SLSA, Sigstore, SBOMs).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
