Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Phishing - Phishing Campaign Targets PyPI With Fake Domain
Phishing Attacks Latest News News & Analysis Security Supply Chain Security

Phishing Campaign Targets PyPI With Fake Domain

Kirsten DoyleBy Kirsten DoyleSeptember 25, 2025Updated:September 25, 20254 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Phishing Targets PyPI
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The phishing wave hasn’t stopped. It has only shifted. 

This week, PyPI users are the target. Attackers are sending emails that look official, asking recipients to “verify their email address” for “account maintenance and security procedures.”  

The message warns of suspension if ignored. The link, however, points to pypi-mirror.org, a domain unaffiliated with PyPI or the Python Software Foundation. 

If you clicked and entered your credentials, act fast: change your PyPI password and review your Security History for unusual activity. Any signs of compromise should be reported to [email protected]. 

The tactic isn’t new. Earlier this year, PyPI saw a nearly identical campaign, and other open source repositories have been targeted with the same trick. The pattern is clear. Bad actors will keep registering fresh domains and sending convincing emails until they hit enough victims. 

What PyPI is Doing 

Stopping phishing isn’t straightforward. Only phishing-resistant two-factor authentication, like hardware tokens, could cut these attacks off completely. In the meantime, PyPI maintainers are: 

  • Working with registrars and CDNs to shut down malicious domains. 
  • Adding phishing sites to blocklists so browsers warn users before they click. 
  • Coordinating with other package managers for faster takedowns. 
  • Exploring stronger TOTP protections against phishing. 

What Maintainers Can Do 

Maintainers have their own role in slowing the spread: 

  • Never click links in unexpected emails. 
  • Rely on password managers with domain-based autofill—if it doesn’t trigger, be suspicious. 
  • Use hardware keys or other phishing-resistant 2FA. 
  • When unsure, ask for help and share suspicious emails. 
  • Spread the word. PyPI isn’t the only open source service in the crosshairs. 

The attacks are simple, but the defense requires discipline. Phishing thrives on haste and trust. Slow down, verify, and keep your guard up. 

A High-Severity Supply Chain Risk 

Jason Soroko, Senior Fellow at Sectigo, says this is a high severity supply chain risk. “A single compromised maintainer account can seed malware into widely used packages and the blast radius extends to CI systems and production. 

“The lure uses convincing language and lookalike domains that defeat quick visual checks, so even seasoned developers can be caught. Because open source ecosystems are highly transitive, one tainted update can cascade through thousands of downstream builds in hours. Treat it as a credible attempt to weaponize software distribution and not just another phishing wave,” he adds. 

Soroko advises that organizations harden publishing identities and pipelines now. “Require phishing-resistant MFA with passkeys or hardware security keys on PyPI and source control accounts and remove SMS.” 

Prefer Trusted Publishing or OIDC-based releases to avoid long-lived API tokens and restrict who can release, he says. 

“Enforce pre-publish reviews and change control, rotate tokens, and monitor PyPI Security History and CI logs for anomalous actions. Pin dependencies with hashes, maintain lockfiles, and alert on unexpected package names or registries in build manifests. Train maintainers to navigate directly to pypi.org instead of using email links and prepare a rollback and token rotation playbook in case a maintainer account is compromised.” 

Build Resilience 

Shane Barney, Chief Information Security Officer at Keeper Security, adds that phishing isn’t going away – it’s evolving. “Attackers will always find new domains to mimic, but organizations can make those attempts far less effective. The goal for security leaders isn’t to chase every domain, but to build resilience so one bad click doesn’t become a breach.” 

That starts with enforcing phishing-resistant MFA, like YubiKeys, for developers and admins, adds Barney. “Pairing that with password managers that auto-fill only on trusted domains closes off the most common entry points. On the enterprise side, privileged access management is the failsafe – enforcing least privilege, limiting lateral movement, and monitoring activity so that even if malicious code slips through, it can’t run unchecked. It’s not about eliminating risk, it’s about putting enough guardrails in place that a single compromised credential doesn’t cascade into a larger incident.” 

Kirsten Doyle
Kirsten Doyle
Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

  • Kirsten Doyle
    Palo Alto warns of active exploitation of GlobalProtect authentication bypass flaw
  • Kirsten Doyle
    CrowdStrike, Google, and Shadowserver Foundation disrupt Glassworm botnet
  • Kirsten Doyle
    Threat Actors Deploy Tiflux RMM for Persistent Remote Access
  • Kirsten Doyle
    Major US telecom providers debut C2 ISAC to counter AI-driven threats

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

New Phishing Kit Starkiller Defeats Multi-Factor Authentication

February 23, 20264 Mins Read

ReliaQuest Uncovers Social Media Phishing Campaign Built on Trusted Tools

January 22, 20266 Mins Read

What Happens after a Phishing Email Lands in Your Inbox?

January 5, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}