logo

PyPI tackles domain resurrection: Why it matters — and what’s missing

ID: 25fc885a-9415-54c3-8887-0d9bbc7e4f0f

STIX ID: report--25fc885a-9415-54c3-8887-0d9bbc7e4f0f

Feed Name: ReversingLabs Blog

Date Published: 2025-09-04

Date Updated: 2026-04-29

Author: Jaikumar Vijayan

...
...

PyPI will automatically invalidate maintainer emails from expired domains to block domain-resurrection account takeovers, reducing supply-chain risk from hijacked packages; the move, already de-verifying ~1,800 addresses with periodic status checks, is a low-friction control that other repos (npm, RubyGems, Maven Central) are urged to adopt. The piece outlines attackers’ favorite package-repo TTPs (account takeover, dependency confusion, typosquatting), notes persistent gaps (account recovery, orphaned projects, weak defaults, opaque ownership transfers), and calls for stronger baselines such as MFA, integrity safeguards, cryptographic signing, and provenance frameworks (SLSA, Sigstore, SBOMs).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.