PyPI, the Python Package Index, has issued a critical security advisory urging all users to reset their credentials following a surge in sophisticated phishing attacks targeting its platform. These attacks have been designed to steal user credentials and compromise package integrity, posing a significant risk to the Python development community. The phishing campaigns employ deceptive emails and fake login pages that mimic the official PyPI interface, tricking users into divulging sensitive information. PyPI's security team has responded swiftly by enhancing monitoring and implementing additional safeguards to protect user accounts and packages. Users are strongly advised to change their passwords immediately, enable two-factor authentication, and remain vigilant against suspicious communications. This incident highlights the ongoing threat of phishing in software supply chains and the importance of proactive security measures. Developers and organizations relying on PyPI packages should review their security practices and ensure their environments are protected against credential theft and potential supply chain attacks. Staying informed and cautious is essential to maintaining the integrity and security of open-source software ecosystems.
This Cyber News was published on www.bleepingcomputer.com. Publication date: Wed, 24 Sep 2025 13:18:11 +0000