Experts warn of the first known phishing attack against PyPISecurity Affairs·Aug 28, 15:36 UTC · Aug 28, 2022Phishing & fraud55
Researchers Find Over 22,000 Removed PyPI Packages at Risk of Revival HijackThe Hacker News·Sep 5, 09:14 UTC · Sep 5, 2024Exploit / PoC in the wild60
PyPI Blocks 1,800 Expired-Domain Emails to Prevent Account Takeovers and Supply Chain AttacksThe Hacker News·Aug 19, 17:29 UTC · Aug 19, 2025Threat actor60
PyPI Repository Warns Python Project Maintainers About Ongoing Phishing AttacksThe Hacker News·Aug 26, 05:01 UTC · Aug 26, 2022Phishing & fraud55
Python team fixes bug that allowed takeover of PyPI repositoryThe Record·Dec 14, 00:00 UTC · Dec 14, 2022Vulnerability155
PyPI Python Package Repository Patches Critical Supply Chain FlawThe Hacker News·Aug 2, 10:50 UTC · Aug 2, 2021Vulnerability155
PyPI Revival Hijack Puts Thousands of Applications at RiskInfosecurity Magazine·Sep 5, 17:00 UTC · Sep 5, 2024Exploit / PoC in the wild60
Six typosquatting packages in PyPI repository laced with crypto minerSecurity Affairs·Jun 28, 06:46 UTC · Jun 28, 2021Vulnerability55
Experts found 3 malicious packages hiding crypto miners in PyPi repositorySecurity Affairs·Jan 4, 15:43 UTC · Jan 4, 2024Malware55
New Malicious Python Libraries Found on PyPI RepositoryInfosecurity Magazine·Aug 9, 17:30 UTC · Aug 9, 2022Malware155
JuiceLedger Hackers Behind the Recent Phishing Attacks Against PyPI UsersThe Hacker News·Sep 5, 06:22 UTC · Sep 5, 2022Phishing & fraud55
PyPI Repository Enforces 2FA for Critical Python ProjectsInfosecurity Magazine·Jul 11, 16:05 UTC · Jul 11, 2022Industry155
PyPI Repository Makes 2FA Security Mandatory for Critical Python ProjectsThe Hacker News·Jul 11, 05:23 UTC · Jul 11, 2022Industry155
Week in review: NIST updates DNS security guidance, compromised LiteLLM PyPI packagesHelp Net Security·Mar 29, 00:00 UTC · Mar 29, 2026Exploit / PoC in the wildCVE-2025-53521CVE-2026-21992CVE-2026-305560
Two Additional Malicious Python Libraries Found on PyPI RepositoryInfosecurity Magazine·Aug 16, 17:30 UTC · Aug 16, 2022Vulnerability155
Popular PyPI Package 'ctx' and PHP Library 'phpass' Hijacked to Steal AWS KeysThe Hacker News·May 26, 02:35 UTC · May 26, 2022Malware155
⚡ THN Weekly Recap: Router Hacks, PyPI Attacks, New Ransomware Decryptor, and MoreThe Hacker News·May 6, 07:05 UTC · May 6, 2025RansomwareCVE-2025-21590CVE-2025-24983CVE-2025-24984+27 CVEs160
GCP Cloud Composer Bug Let Attackers Elevate Access via Malicious PyPI PackagesThe Hacker News·Apr 22, 14:06 UTC · Apr 22, 2025Vulnerability55
Malicious PyPI Package Exposes Crypto Wallets to Infostealer CodeInfosecurity Magazine·Nov 28, 17:15 UTC · Nov 28, 2024Malware55
PyPI Attack: ChatGPT, Claude Impersonators Deliver JarkaStealer via Python LibrariesThe Hacker News·Nov 23, 06:39 UTC · Nov 23, 2024Malware155
Software supply chain attacks are getting easierHelp Net Security·Jan 24, 00:00 UTC · Jan 24, 2024Malware55
Week in review: RCE bug in GitLab patched, phishing PyPI users, Escanor malware in MS Office docsHelp Net Security·Aug 28, 00:00 UTC · Aug 28, 2022VulnerabilityCVE-2022-288460
Newly Uncovered PyPI Package Drops Fileless Cryptominer to Linux SystemsThe Hacker News·Aug 15, 00:00 UTC · Aug 15, 2022Malware55
10 Credential Stealing Python Libraries Found on PyPI RepositoryThe Hacker News·Aug 10, 05:22 UTC · Aug 10, 2022Malware55
Anthropic says its AI hacked realThe Record·Jul 31, 12:16 UTC · Jul 31, 2026Data breach in the wild60
The serpent’s tongue: Luring the Python out of its denCisco Talos·Jul 14, 10:00 UTC · Jul 14, 2026Malware155
GitHub Token Leak Exposes Python's Core Repositories to Potential AttacksThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2024Exploit / PoC in the wild160
Open-source security group pulls out of U.S. grant, citing DEI restrictionsCyberScoop·Oct 29, 20:55 UTC · Oct 29, 2025Exploit / PoC in the wild160
Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for ItselfThe Hacker News·Aug 5, 07:53 UTC · Aug 5, 2026Malware55
How LiteLLM Turned Developer Machines Into Credential Vaults for AttackersThe Hacker News·Apr 8, 10:59 UTC · Apr 8, 2026Vulnerability155
⚡ Weekly Recap: IoT Exploits, Wallet Breaches, Rogue Extensions, AI Abuse & MoreThe Hacker News·Jan 5, 12:56 UTC · Jan 5, 2026VulnerabilityCVE-2025-55182CVE-2025-13915CVE-2025-52691+7 CVEs60
⚡ Weekly Recap: Fortinet Exploit, Chrome 0-Day, BadIIS Malware, Record DDoS, SaaS Breach & MoreThe Hacker News·Nov 24, 12:32 UTC · Nov 24, 2025Malware in the wildCVE-2025-58034CVE-2025-64446CVE-2025-13223+12 CVEs60
Webinar: How to Stop Python Supply Chain Attacks—and the Expert Tools You NeedThe Hacker News·Aug 7, 15:33 UTC · Aug 7, 2025Vulnerability55
Review of supply chain attacks in 2024 and potential disruption scenarios for 2025Kaspersky Securelist·Dec 9, 10:54 UTC · Dec 9, 2024Data breach in the wild60
Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three OrganizationsThe Hacker News·Jul 31, 16:17 UTC · Jul 31, 2026Data breach160
Anthropic says its AI accidentally hacked three companies during safety testsCyberScoop·Jul 31, 02:10 UTC · Jul 31, 2026Exploit / PoC in the wild160
⚡ Weekly Recap: Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and MoreThe Hacker News·Jun 15, 00:00 UTC · Jun 15, 2026Malware in the wildCVE-2026-11645CVE-2026-2441CVE-2026-3909+23 CVEs160
GitHub Breached — Employee Device Hack Led to Exfiltration of 3,800+ Internal ReposThe Hacker News·May 20, 16:10 UTC · May 20, 2026Data breach60