thepsf.bsky.social
@thepsf.bsky.social
Reposted
Incident Report of the recent #PyPI Phishing Campaign

TL,DR:
• PyPI was not breached
• PyPI users were targeted with phishing emails
• A single project saw uploads with malicious code and those releases have been removed

blog.pypi.org/posts/2025-0...

#Python #OpenSource #Security
PyPI Phishing Attack: Incident Report - The Python Package Index Blog
Follow-up on the recent phishing attack targeting PyPI users.
blog.pypi.org
July 31, 2025 at 4:59 PM