Application Security New GitHub, PyPI Policies Boost Supply Chain Security Dependabot gets a three-day cooldown window before opening pull requests, and PyPI rejects file uploads to releases older than 14 days. Ionut ArghireJuly 27, 2026
Malware & Threats Over 100 NPM, PyPI Packages Hit in New Shai-Hulud Supply Chain Attacks The most recent variants of the self-propagating attacks are named Miasma and Hades. Ionut ArghireJune 9, 2026
Malware & Threats Telnyx Targeted in Growing TeamPCP Supply Chain Attack Two malicious versions of the popular SDK were uploaded to the PyPI registry, targeting Windows, macOS, and Linux. Ionut ArghireMarch 30, 2026
Application Security From Trivy to Broad OSS Compromise: TeamPCP Hits Docker Hub, VS Code, PyPI The hackers compromised GitHub Action tags, then shifted to NPM, Docker Hub, VS Code, and PyPI, and teamed with Lapsus$. Ionut ArghireMarch 25, 2026
Phishing PyPI Warns Users of Fresh Phishing Campaign Threat actors impersonating PyPI ask users to verify their email for security purposes, directing them to fake websites. Ionut ArghireSeptember 25, 2025
Malware & Threats Developers Targeted With Malware Disguised as DeepSeek Package Python developers looking to integrate DeepSeek into their projects were targeted with malicious packages delivered through PyPI. Eduard KovacsFebruary 4, 2025
Malware & Threats Cryptocurrency Wallets Targeted via Python Packages Uploaded to PyPI Multiple Python packages referencing dependencies containing cryptocurrency-stealing code were published to PyPI. Ionut ArghireOctober 2, 2024
Malware & Threats Malware Upload Attack Hits PyPI Repository Maintainers of the Python Package Index (PyPI) repository were forced to suspend new project creation and new user registration to mitigate a malware upload... Ryan NaraineMarch 28, 2024
Application Security PyPI Packages Found to Expose Thousands of Secrets GitGuardian discovered roughly 4,000 secrets in nearly 3,000 PyPI packages, including Azure, AWS, and GitHub keys. Ionut ArghireNovember 14, 2023
Identity & Access PyPI Enforcing 2FA for All Project Maintainers to Boost Security PyPI will require all accounts that maintain a project to enable two-factor authentication (2FA) by the end of 2023. Ionut ArghireMay 30, 2023