Administrators of the Python Package Index (PyPI) have reported unauthorized access to 174 user accounts on the service. According to PyPI representatives, the authentication details of the affected users were obtained from collections of previously compromised credentials from hacks or data leaks from other services. Access to the accounts on PyPI was gained due to victims reusing the same passwords across different sites and not enabling two-factor authentication in the PyPI catalog.
The activity of the attackers was detected after a series of complaints from users who reported receiving notifications from PyPI about the activation of two-factor authentication, even though they had not logged into their accounts at that time nor made any changes. Analysis of the logs revealed unauthorized access to the accounts of 174 users. No signs of package tampering or other malicious activity were found — all actions of the attackers were limited to unauthorized access and account changes.
The affected accounts were suspended pending the investigation, and all other PyPI users who had not enabled two-factor authentication were notified and a process for re-verifying their email was initiated. In total, two-factor authentication was not enabled for 370,000 users (56%) of the catalog.
Source: opennet.ru
