logo

PyPI Halts Sign-Ups Amid Surge of Malicious Package Uploads Targeting Developers

ID: 89400a76-c305-546e-b232-10b845ae6883

STIX ID: report--89400a76-c305-546e-b232-10b845ae6883

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2024-03-29

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

PyPI was targeted by a large typosquatting campaign (starting March 26, 2024) that uploaded hundreds of malicious packages mimicking popular Python libraries (including ML-related packages). The malicious installers check for Windows, then download an obfuscated stealer from an actor-controlled domain that exfiltrates browser data, Discord tokens, files, and crypto-wallet data, installs a persistence script in Startup, and attempts further payloads; multiple vendors (Checkmarx, Mend.io, Phylum, Check Point) confirmed detections and PyPI temporarily halted new project creation and user sign-ups to mitigate the attack.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.