PyPI maintainers alert users to email verification phishing attackSecurity Affairs·Jul 30, 13:16 UTC · Jul 30, 2025Phishing & fraud30
Experts warn of the first known phishing attack against PyPISecurity Affairs·Aug 28, 15:36 UTC · Aug 28, 2022Phishing & fraud55
OceanLotus suspected of distributing ZiChatBot malware via wheel packages in PyPIKaspersky Securelist·May 5, 14:33 UTC · May 5, 2026Malware42
PyPI Warns of Ongoing Phishing Campaign Using Fake Verification Emails and Lookalike DomainThe Hacker News·Jul 31, 10:03 UTC · Jul 31, 2025Threat actor45
Researchers Find Over 22,000 Removed PyPI Packages at Risk of Revival HijackThe Hacker News·Sep 5, 09:14 UTC · Sep 5, 2024Exploit / PoC in the wild60
PyPI Blocks 1,800 Expired-Domain Emails to Prevent Account Takeovers and Supply Chain AttacksThe Hacker News·Aug 19, 17:29 UTC · Aug 19, 2025Threat actor160
PyPI Introduces Archival Status to Alert Users About Unmaintained Python PackagesThe Hacker News·Feb 3, 12:30 UTC · Feb 3, 2025Industry142
Developer account body snatchers pose risks to the software supply chainCisco Talos·Oct 4, 12:51 UTC · Oct 4, 2022Exploit / PoC57
PyPI Repository Warns Python Project Maintainers About Ongoing Phishing AttacksThe Hacker News·Aug 26, 05:01 UTC · Aug 26, 2022Phishing & fraud55
Malicious PyPI, npm, and Ruby Packages Exposed in Ongoing OpenThe Hacker News·Jun 4, 10:11 UTC · Jun 4, 2025Vulnerability242
Python team fixes bug that allowed takeover of PyPI repositoryThe Record·Dec 14, 00:00 UTC · Dec 14, 2022Vulnerability155
Malicious Package on PyPI Hides Behind Image Files, Spreads Via GitHubInfosecurity Magazine·Nov 9, 17:00 UTC · Nov 9, 2022Threat actor145
JuiceLedger Hacker Linked to First Phishing Campaign Targeting PyPI UsersInfosecurity Magazine·Sep 2, 15:00 UTC · Sep 2, 2022Threat actor57
PyPI Python Package Repository Patches Critical Supply Chain FlawThe Hacker News·Aug 2, 10:50 UTC · Aug 2, 2021Vulnerability155
Malicious npm and PyPI packages Llinked to Lazarus APT fake recruiter campaignSecurity Affairs·Feb 15, 18:14 UTC · Feb 15, 2026Threat actor157
PyPI Revival Hijack Puts Thousands of Applications at RiskInfosecurity Magazine·Sep 5, 17:00 UTC · Sep 5, 2024Exploit / PoC in the wild60
Rogue PyPI Library Solana Users, Steals Blockchain Wallet KeysThe Hacker News·Aug 11, 10:01 UTC · Aug 11, 2024Malware42
PyPI halted new users and projects while it fended off supplyArs Technica · Security·Mar 28, 18:50 UTC · Mar 28, 2024Malware42
Experts found potential remote code execution in PyPISecurity Affairs·Aug 3, 08:27 UTC · Aug 3, 2021Vulnerability42
Six typosquatting packages in PyPI repository laced with crypto minerSecurity Affairs·Jun 28, 06:46 UTC · Jun 28, 2021Vulnerability55
TeamPCP strikes again: Backdoored Telnyx PyPI package delivers malwareHelp Net Security·Mar 27, 00:00 UTC · Mar 27, 2026Malware42
Popular PyPI site for developers temporarily blocks functions due to malware campaignThe Record·Mar 28, 19:11 UTC · Mar 28, 2024Malware42
Experts found 3 malicious packages hiding crypto miners in PyPi repositorySecurity Affairs·Jan 4, 15:43 UTC · Jan 4, 2024Malware55
Malicious PyPI Packages Use Compiled Python Code to Bypass DetectionInfosecurity Magazine·Jun 2, 16:30 UTC · Jun 2, 2023Ransomware157
Researchers Discover Malicious PyPI Package Posing as SentinelOne SDK to Steal DataThe Hacker News·Dec 20, 05:29 UTC · Dec 20, 2022Malware42
10 malicious packages on PyPI used to steal developers' dataSecurity Affairs·Aug 10, 15:14 UTC · Aug 10, 2022Malware42
New Malicious Python Libraries Found on PyPI RepositoryInfosecurity Magazine·Aug 9, 17:30 UTC · Aug 9, 2022Malware155
PyPI hardens package security with new upload restrictionsHelp Net Security·Jul 23, 00:00 UTC · Jul 23, 2026Vulnerability130
PyPI Packages Deliver ZiChatBot Malware via Zulip APIs on Windows and LinuxThe Hacker News·May 7, 09:20 UTC · May 7, 2026Malware42
TeamPCP Pushes Malicious Telnyx Versions to PyPI, Hides Stealer in WAV FilesThe Hacker News·Mar 28, 06:25 UTC · Mar 28, 2026Malware42
Compromised dYdX npm and PyPI Packages Deliver Wallet Stealers and RAT MalwareThe Hacker News·Feb 6, 08:40 UTC · Feb 6, 2026Malware42
RubyGems, PyPI Hit by Malicious Packages Stealing Credentials, Crypto, Forcing Security ChangesThe Hacker News·Aug 9, 06:49 UTC · Aug 9, 2025Vulnerability42
PyPI Python Library "aiocpa" Found Exfiltrating Crypto Keys via Telegram BotThe Hacker News·Nov 29, 08:53 UTC · Nov 29, 2024Malware42
Dormant PyPI Package Compromised to Spread Nova Sentinel MalwareThe Hacker News·Feb 23, 17:08 UTC · Feb 23, 2024Malware42
PyPI enforces 2FA to prevent maintainers' account takeoverSecurity Affairs·May 30, 17:37 UTC · May 30, 2023Malware42
PyPI Repository Under Attack: User Sign-Ups and Package Uploads Temporarily HaltedThe Hacker News·May 23, 06:19 UTC · May 23, 2023Malware42
W4SP Stealer Discovered in Multiple PyPI Packages Under Various NamesThe Hacker News·Dec 30, 05:06 UTC · Dec 30, 2022Malware142