The administrators of the Python Package Index (PyPI) lifted the ban after it was revealed that 1,500 projects were created not by malicious actors, but by a security team at VK, which owns the domain inbox.ru. The intention was stated to be activities aimed at preventing potential attacks on external libraries used in VK. VK representatives apologized and assured that they would no longer register projects in this manner to identify and prevent attacks.
It is worth noting that last week, PyPI blocked the use of @inbox.ru email addresses for creating new projects due to the registration of over 1,500 projects that were allegedly intended for attacking users following chat bot recommendations or mistyping package names. The projects used names of nonexistent libraries mistakenly recommended by large language models (slopdquotting) or names similar to popular projects.
Source: opennet.ru
