Python developers attacked with dangerous phishing attacks: this is how to stay safe




  • The developers who published PyPI projects with their email in package metadata are being attacked
  • They are asked to “verify” your email address with a false pypi platform
  • The “verification” process transmits login credentials to the attackers

Python developers are being attacked with dangerous Phishing attacks, warned the Python Software Foundation (PSF).

PSF said the threat actors were actively attacking developers who have published PyPI projects with their email in package metadata. These developers receive emails that ask them to “verify” their email address on the platform, providing a link to do so.

Leave a Comment

Your email address will not be published. Required fields are marked *