Security News > 2022 > August > PyPI packages hijacked after developers fall for phishing emails

PyPI packages hijacked after developers fall for phishing emails
2022-08-25 11:18

A phishing campaign caught yesterday was seen targeting maintainers of Python packages published to the PyPI registry.

Python packages 'exotel' and 'spam' are among hundreds seen laced with malware after attackers successfully compromised accounts of maintainers who fell for the phishing email.

Admins of the PyPI registry confirmed yesterday a phishing email campaign had actively been targeting PyPI maintainers after Django project board member Adam Johnson reported receiving a suspicious email.

Background: the phishing message claims that there is a mandatory 'validation' process being implemented, and invites users to follow a link to validate a package, or otherwise risk the package being removed from PyPI. pic.

Some developers did fall for the phishing emails and entered their credentials on the attacker's webpage, leading to their creations getting hijacked and laced with malware.

This development follows May's hijack of the popular PyPI library 'ctx' that had prompted PyPI admins to mandate two-factor authentication for maintainers of critical projects.


News URL

https://www.bleepingcomputer.com/news/security/pypi-packages-hijacked-after-developers-fall-for-phishing-emails/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Pypi 15 0 0 1 15 16