PyPL is blocking hundreds of expired domains to stop malware attacks




  • Domain resurrection attacks allow cybercriminals to exploit users of the trust in Pypi
  • By scanning for expired domains, Pypi aims to stop these attacks
  • Users are still recommended to activate 2FA and add secondary emails

The Python (PyPI) package index is ending the so -called “domain resurrection attacks” that have been observed in nature before to launch cyber attacks.

The resurrection of the domain is an attack of the supply chain where a threat actor is recorded, or registered again, a domain that was once owned by a legitimate packages maintainer, but since then it has expired.

Leave a Comment

Your email address will not be published. Required fields are marked *