Due to malicious activity, PyPI has suspended the registration of new users and projects.

The Python package repository PyPI (Python Package Index) has temporarily halted the registration of new users and projects. The reason cited is a surge in malicious activity, where attackers have been publishing packages containing harmful code. It was noted that due to several administrators being on leave, the volume of registered malicious projects last week exceeded the remaining PyPI team's capacity for timely response. Developers plan to restructure some verification processes over the weekend, after which the ability to register in the repository will resume.

According to the monitoring system for malicious activity by Sonatype, 6,933 malicious packages were found in the PyPI directory in March 2023, and since 2019 the total number of identified malicious packages has surpassed 115,000. In December 2022, as a result of an attack on the NuGet, NPM, and PyPI directories, the publication of 144,000 packages containing phishing and spam code was recorded.

Most malicious packages disguise themselves as popular libraries using typosquatting (assigning similar names that differ by a few characters, e.g., exampl instead of example, djangoo instead of django, pyhton instead of python, etc.) — attackers rely on inattentive users who make typos or fail to notice the differences in the name while searching. Malicious actions usually involve sending confidential data found on the local system due to the identification of template files with passwords, access keys, crypto wallets, tokens, session cookies, and other sensitive information.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster