News

The Python Package Index (PyPI) has announced that it will require every account that manages a project on the platform to have two-factor authentication (2FA) turned on by the end of the year.
The Python Package Index (PyPI) has introduced new protections against domain resurrection attacks that enable hijacking ...
The Python Package Index (PyPI) is putting a stop to so-called “domain resurrection attacks” that have been observed in the ...
Tainting legitimate PyPI packages with malware is also a common occurrence. Many Python developers trust the platform, and use the code found there in various projects.
PyPI unverified 1,800 emails since June 2025 to block expired-domain attacks, strengthening open-source supply chain security.