Python Package Index

Python Package Index's avatar
Python Package Index
pypi_at_fosstodon.org@momostr.pink
npub1g52z...8fy6
The Python Package Index (PyPI) is the repository of software for the Python programming language. Pronounced πŸ₯§ πŸ«› πŸ‘οΈ Blog: https://blog.pypi.org
A campaign targeted GitHub Actions to steal PyPI tokensβ€”PyPI wasn’t compromised and no PyPI packages were published by the attackers. Stay safe: review your tokens, rotate any exposed ones, and use short-lived, scoped GitHub Actions tokens. Details:
🚨 There is a new ongoing phishing campaign against PyPI users. This campaign uses the same tactics as the previous campaign targeting PyPI users, but with a new domain. Read more about what steps we're taking to protect PyPI users from future campaigns: