home.social

#pypi — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #pypi, aggregated by home.social.

  1. Did I just hack up an abomination using xmllint (from libxml2) and jq to query the latest #PyPI version of a package? Perhaps.

    Do you no longer have to specify the target version when using pkgbump on PyPI packages? Absolutely.

    gitweb.gentoo.org/proj/mgorny-

    #Gentoo

  2. Did I just hack up an abomination using xmllint (from libxml2) and jq to query the latest #PyPI version of a package? Perhaps.

    Do you no longer have to specify the target version when using pkgbump on PyPI packages? Absolutely.

    gitweb.gentoo.org/proj/mgorny-

    #Gentoo

  3. Did I just hack up an abomination using xmllint (from libxml2) and jq to query the latest #PyPI version of a package? Perhaps.

    Do you no longer have to specify the target version when using pkgbump on PyPI packages? Absolutely.

    gitweb.gentoo.org/proj/mgorny-

    #Gentoo

  4. Did I just hack up an abomination using xmllint (from libxml2) and jq to query the latest #PyPI version of a package? Perhaps.

    Do you no longer have to specify the target version when using pkgbump on PyPI packages? Absolutely.

    gitweb.gentoo.org/proj/mgorny-

    #Gentoo

  5. Did I just hack up an abomination using xmllint (from libxml2) and jq to query the latest #PyPI version of a package? Perhaps.

    Do you no longer have to specify the target version when using pkgbump on PyPI packages? Absolutely.

    gitweb.gentoo.org/proj/mgorny-

    #Gentoo

  6. Latest PyPi Compromise

    A supply chain attack targeting the Microsoft DurableTask Python client compromised versions 1.4.1, 1.4.2, and 1.4.3 on PyPi. The threat actor gained access through a compromised GitHub account previously linked to attacks, using stolen credentials to dump GitHub secrets containing PyPi tokens. The evolved payload targets Linux systems, stealing credentials from AWS, Azure, GCP, Kubernetes, Vault, and password managers like Bitwarden and 1Password. It propagates via AWS SSM and Kubernetes lateral movement, limited to 5 targets per infected host. The payload scrapes shell history, bruteforces password managers, and establishes persistence through infection markers. Compromised packages were quarantined following analysis.

    Pulse ID: 6a0ce3b0ad791179648c47b0
    Pulse Link: otx.alienvault.com/pulse/6a0ce
    Pulse Author: AlienVault
    Created: 2026-05-19 22:26:56

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AWS #Azure #BruteForce #CyberSecurity #GitHub #InfoSec #Linux #Microsoft #OTX #OpenThreatExchange #Password #PyPI #Python #RCE #SupplyChain #Word #bot #AlienVault

  7. One question about #PyPy #PyPi is how many functions like #xz will they NOT find at this point of minimal #Python library backdoors especially iF this is being used in the Enterprise #Fortune1000 and below as a vector IN, eh?

    🐛🚪🚪🚪🚪🚪🚪🚪🚪🚪 🔍👀
    ☣️
    👇
    virustotal.com/graph/embed/ga6