home.social

#pypi — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #pypi, aggregated by home.social.

fetched live
  1. Exhibit N: #pypi apparently only now limiting package file uploads to "only" two weeks after the release itself.

  2. Exhibit N: #pypi apparently only now limiting package file uploads to "only" two weeks after the release itself.

  3. If you use the `setup-uv` #GitHub #Action in your workflows, consider upgrading to version 9.0.0 soon.

    This version changes the default behavior to store the downloaded #Python wheels from #PyPI in GHA Cache, shedding load from PyPI, especially relevant for frequent CI/CD runs.

    The maintainers considered this a breaking change, hence the version bump, probably because it flips existing expectations.

    If you expected that the Action was caching downloads before, now it actually does, so it's a logical fix in that regard.
    Read more: github.com/astral-sh/setup-uv/

  4. If you use the `setup-uv` #GitHub #Action in your workflows, consider upgrading to version 9.0.0 soon.

    This version changes the default behavior to store the downloaded #Python wheels from #PyPI in GHA Cache, shedding load from PyPI, especially relevant for frequent CI/CD runs.

    The maintainers considered this a breaking change, hence the version bump, probably because it flips existing expectations.

    If you expected that the Action was caching downloads before, now it actually does, so it's a logical fix in that regard.
    Read more: github.com/astral-sh/setup-uv/

  5. The Python Package Index now rejects new files published to releases older than 14 days. This mitigation prevents long-stable releases from being poisoned in case publishing tokens or workflows of PyPI projects are compromised.

    blog.pypi.org/posts/2026-07-22

  6. The Python Package Index now rejects new files published to releases older than 14 days. This mitigation prevents long-stable releases from being poisoned in case publishing tokens or workflows of PyPI projects are compromised.

    blog.pypi.org/posts/2026-07-22

    #python #security #supplychain #pypi

  7. #PyPI now displays the #Codeberg logo on links pointing there! Looks way better than the generic "external link" icon :BlobCatHeart:

  8. #PyPI now displays the #Codeberg logo on links pointing there! Looks way better than the generic "external link" icon :BlobCatHeart:

  9. Just released multipart-2.0.0 to #pypi.

    This is a fast and robust #Python parser for multipart/form-data (HTTP form requests) supporting both non-blocking #ASGI and blocking #WSGI applications.

    changelog: multipart.readthedocs.io/en/la

    pypi: pypi.org/project/multipart/

    And when I say 'fast' I mean it: defnull.de/2026/python-multipa

    #SansIO

  10. Just released multipart-2.0.0 to #pypi.

    This is a fast and robust #Python parser for multipart/form-data (HTTP form requests) supporting both non-blocking #ASGI and blocking #WSGI applications.

    changelog: multipart.readthedocs.io/en/la

    pypi: pypi.org/project/multipart/

    And when I say 'fast' I mean it: defnull.de/2026/python-multipa

    #SansIO

  11. Today's the day! Come on out for story time and good ideas when I share details on the Anatomy of a Phishing Campaign I handled for #PyPI around this time last year.

    ep2026.europython.eu/session/a

    #EuroPython2026 #EP2026 #Python #OpenSource #SupplyChain #Security

  12. Today's the day! Come on out for story time and good ideas when I share details on the Anatomy of a Phishing Campaign I handled for #PyPI around this time last year.

    ep2026.europython.eu/session/a

    #EuroPython2026 #EP2026 #Python #OpenSource #SupplyChain #Security

  13. Compromised npm Packages in the AsyncAPI Namespace Deliver Miasma Botnet Loader

    Four npm packages in the AsyncAPI namespace were compromised to distribute a multi-stage botnet loader called Miasma. The attack utilized trusted GitHub Actions publishing but originated from a poisoned source commit. Malicious code was injected into legitimate source files that execute when imported, launching a detached Node.js process to download an 8.25 MB encrypted payload from IPFS. The final payload is a sophisticated tasking framework supporting multiple command-and-control channels including REST, Nostr relays, IPFS, Ethereum smart contracts, and BitTorrent DHT. The framework establishes persistence via systemd services on Linux and fake NodeJS directories, supporting file operations, shell execution, data collection, and cross-ecosystem propagation capabilities for npm, PyPI, RubyGems, and Cargo ecosystems.

    Pulse ID: 6a5665a177561cba872b779e
    Pulse Link: otx.alienvault.com/pulse/6a566
    Pulse Author: AlienVault
    Created: 2026-07-14 16:36:49

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #GitHub #InfoSec #Linux #NPM #Nodejs #OTX #OpenThreatExchange #PyPI #RAT #RCE #Rust #bot #botnet #AlienVault

  14. Compromised npm Packages in the AsyncAPI Namespace Deliver Miasma Botnet Loader

    Four npm packages in the AsyncAPI namespace were compromised to distribute a multi-stage botnet loader called Miasma. The attack utilized trusted GitHub Actions publishing but originated from a poisoned source commit. Malicious code was injected into legitimate source files that execute when imported, launching a detached Node.js process to download an 8.25 MB encrypted payload from IPFS. The final payload is a sophisticated tasking framework supporting multiple command-and-control channels including REST, Nostr relays, IPFS, Ethereum smart contracts, and BitTorrent DHT. The framework establishes persistence via systemd services on Linux and fake NodeJS directories, supporting file operations, shell execution, data collection, and cross-ecosystem propagation capabilities for npm, PyPI, RubyGems, and Cargo ecosystems.

    Pulse ID: 6a5665a177561cba872b779e
    Pulse Link: otx.alienvault.com/pulse/6a566
    Pulse Author: AlienVault
    Created: 2026-07-14 16:36:49

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #GitHub #InfoSec #Linux #NPM #Nodejs #OTX #OpenThreatExchange #PyPI #RAT #RCE #Rust #bot #botnet #AlienVault

  15. Coordinated npm and PyPI Campaign Typosquats Popular Secure Payment Apps

    Pulse ID: 6a546e33879dc2bce62e418f
    Pulse Link: otx.alienvault.com/pulse/6a546
    Pulse Author: Tr1sa111
    Created: 2026-07-13 04:48:51

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #NPM #OTX #OpenThreatExchange #PyPI #bot #Tr1sa111

  16. Coordinated npm and PyPI Campaign Typosquats Popular Secure Payment Apps

    Pulse ID: 6a546e33879dc2bce62e418f
    Pulse Link: otx.alienvault.com/pulse/6a546
    Pulse Author: Tr1sa111
    Created: 2026-07-13 04:48:51

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #NPM #OTX #OpenThreatExchange #PyPI #bot #Tr1sa111

  17. rainlog 1.1.0

    - New **Comparison** chart mode: press `m` in monthly or yearly grouping to see year-over-year bars side by side.

    #Python #PyPI #Rain #Weather #OpenSource

  18. quicktipp #117: Bootstrapping a portable Python bundle on MS Windows using the `pywinbundle` tool.

    github.com/christian-korneck/p

    A bundle is a bit like a venv, but self-contained and can get moved/renamed to any path or copied to any Windows machine. The bundle will continue to work, even if there is no existing Python installation.

    #python #windows #pip #venv #virtualenv #uv #jupyter #pypi

  19. quicktipp #117: Bootstrapping a portable Python bundle on MS Windows using the `pywinbundle` tool.

    github.com/christian-korneck/p

    A bundle is a bit like a venv, but self-contained and can get moved/renamed to any path or copied to any Windows machine. The bundle will continue to work, even if there is no existing Python installation.

    #python #windows #pip #venv #virtualenv #uv #jupyter #pypi

  20. Один комментарий на Хабре — и ещё один пакет для Django Admin

    Недавно я опубликовал на Хабре статью о небольшом пакете django-scroll-to-top , который добавляет кнопку «Наверх» в проекты на Django. Сам пакет решает довольно локальную задачу, но обсуждение под статьёй оказалось интереснее, чем я ожидал. В комментариях возник вполне закономерный вопрос: насколько вообще подобным интерфейсным дополнениям место в стандартной Django Admin? Ведь каждое установленное приложение добавляет свои пункты в боковое меню, и со временем административная панель действительно может начать выглядеть перегруженной. Один из комментариев заставил меня посмотреть на эту проблему немного под другим углом. В результате вместо долгого спора появился ещё один небольшой open-source-пакет — теперь уже для сворачивания групп приложений в боковой панели Django Admin.

    habr.com/ru/articles/1057784/

    #Django #Django_Admin #Python #open_source #PyPI #UX #cookie #плагины_Django #административная_панель #django_admin_collapse_apps

  21. Coordinated npm and PyPI Campaign Typosquats Popular Secure Payment Apps

    A cluster of npm and PyPI packages typosquatting popular payment applications has been detected by Socket's AI scanner, which automatically blocks malicious packages in your code, as well as preventing them from being published.

    Pulse ID: 6a50a4bc4687b8b6b035b1a5
    Pulse Link: otx.alienvault.com/pulse/6a50a
    Pulse Author: CyberHunter_NL
    Created: 2026-07-10 07:52:28

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #NPM #OTX #OpenThreatExchange #PyPI #TypoSquatting #bot #CyberHunter_NL

  22. Coordinated npm and PyPI Campaign Typosquats Popular Secure Payment Apps

    A cluster of npm and PyPI packages typosquatting popular payment applications has been detected by Socket's AI scanner, which automatically blocks malicious packages in your code, as well as preventing them from being published.

    Pulse ID: 6a50a4bc4687b8b6b035b1a5
    Pulse Link: otx.alienvault.com/pulse/6a50a
    Pulse Author: CyberHunter_NL
    Created: 2026-07-10 07:52:28

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #NPM #OTX #OpenThreatExchange #PyPI #TypoSquatting #bot #CyberHunter_NL

  23. Coordinated npm and PyPI Campaign Typosquats Popular Secure Payment Apps

    Socket's AI scanner identified 17 malicious packages across npm and PyPI ecosystems published simultaneously on July 7, 2026. The packages typosquatted legitimate PaySafe, Skrill, and Neteller payment SDK names to steal developer credentials and tokens. The malware implements sophisticated anti-analysis techniques including sandbox detection based on CPU cores and hostname patterns, multi-layer C2 domain obfuscation using XOR encoding, and selective activation gating. Upon execution, the packages exfiltrate environment variables containing API keys, secrets, tokens, and authentication credentials to AWS-hosted infrastructure via an ngrok endpoint. The campaign demonstrates coordinated cross-ecosystem capabilities, proper operational security through varied obfuscation keys, and knowledge of defender technologies, suggesting an organized threat actor with financial motivation.

    Pulse ID: 6a4d89817cfad2c0f464e67a
    Pulse Link: otx.alienvault.com/pulse/6a4d8
    Pulse Author: AlienVault
    Created: 2026-07-07 23:19:29

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AWS #CyberSecurity #Edge #Endpoint #InfoSec #Malware #NPM #OTX #OpenThreatExchange #PyPI #RAT #bot #AlienVault

  24. Coordinated npm and PyPI Campaign Typosquats Popular Secure Payment Apps

    Socket's AI scanner identified 17 malicious packages across npm and PyPI ecosystems published simultaneously on July 7, 2026. The packages typosquatted legitimate PaySafe, Skrill, and Neteller payment SDK names to steal developer credentials and tokens. The malware implements sophisticated anti-analysis techniques including sandbox detection based on CPU cores and hostname patterns, multi-layer C2 domain obfuscation using XOR encoding, and selective activation gating. Upon execution, the packages exfiltrate environment variables containing API keys, secrets, tokens, and authentication credentials to AWS-hosted infrastructure via an ngrok endpoint. The campaign demonstrates coordinated cross-ecosystem capabilities, proper operational security through varied obfuscation keys, and knowledge of defender technologies, suggesting an organized threat actor with financial motivation.

    Pulse ID: 6a4d89817cfad2c0f464e67a
    Pulse Link: otx.alienvault.com/pulse/6a4d8
    Pulse Author: AlienVault
    Created: 2026-07-07 23:19:29

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AWS #CyberSecurity #Edge #Endpoint #InfoSec #Malware #NPM #OTX #OpenThreatExchange #PyPI #RAT #bot #AlienVault

  25. Malicious code detected: tronsev v0.0.1 (PyPI) — HIGH severity. Exfiltrates private keys, targets crypto users. No CVE, no active exploitation. Avoid installation & verify packages. radar.offseq.com/threat/mal-20 #OffSeq #PyPI #Crypto #ThreatIntel

  26. If you use GitHub Actions to publish to #PyPI, I wrote a blog post outlining what I consider the key things you can do to secure your publishing workflow.

    snarky.ca/how-to-publi...

    If you don't use GitHub Actions for publishing, this post will NOT be of interest to you.

    How to publish to PyPI using G...

  27. TODO: A zero dependency #python app can be installed with

    - git clone
    - or download zip,
    executed with python -m

    But you can't search #pypi for these apps.

  28. TODO: A zero dependency #python app can be installed with

    - git clone
    - or download zip,
    executed with python -m

    But you can't search #pypi for these apps.

  29. Da un runner Jenkins ad Amazon Redshift: come il worm Shai-Hulud trasforma una CI/CD in una breach cloud

    FortiGuard Labs ricostruisce una compromissione partita da un pacchetto npm infetto da Shai-Hulud: in poche ore l'attaccante passa da un Jenkins runner a pieni privilegi amministrativi su AWS, fino a esfiltrare dati da un cluster Amazon Redshift in produzione.

    insicurezzadigitale.com/da-un-

  30. Da un runner Jenkins ad Amazon Redshift: come il worm Shai-Hulud trasforma una CI/CD in una breach cloud

    FortiGuard Labs ricostruisce una compromissione partita da un pacchetto npm infetto da Shai-Hulud: in poche ore l'attaccante passa da un Jenkins runner a pieni privilegi amministrativi su AWS, fino a esfiltrare dati da un cluster Amazon Redshift in produzione.

    insicurezzadigitale.com/da-un-

  31. Is there any way to report a #Python #PyPI package as junk? Not malicious, but no/example code.

  32. Is there any way to report a #Python #PyPI package as junk? Not malicious, but no/example code.

  33. #Python: Attackers Planted a #Telegram-Powered Backdoor #Malware Across Fake 'pyrogram' Packages on #PyPI:
    * pyrogram-navy
    * pyrogram-styled
    * sepgram
    * pyrogram-kelra

    ...and others - check out the @CheckmarxZero blog post for more details:
    👇
    checkmarx.com/zero-post/operat

  34. #Python: Attackers Planted a #Telegram-Powered Backdoor #Malware Across Fake 'pyrogram' Packages on #PyPI:
    * pyrogram-navy
    * pyrogram-styled
    * sepgram
    * pyrogram-kelra

    ...and others - check out the @CheckmarxZero blog post for more details:
    👇
    checkmarx.com/zero-post/operat

  35. RE: fosstodon.org/@europython/1167

    Very excited to share stories, insights, recommendations at my first @europython

    I'll also be attending the Packaging and Language Summits, as well as any other opportunities to increase awareness of #Python and #PyPI #OpenSource #SupplyChain #Security initiatives.

    #EP2026 #TooManyHashtags #SorryNotSorry

  36. Great coverage from @lwn of the PSF PyPI Safety & Security Engineer @miketheman's talk on Trusted Publishing at Open Source Summit. 36% of @pypi uploads now use Trusted Publishing. Is yours one of them?

    lwn.net/Articles/1076205/

    #Python #PyPI #OSSumit #Security

  37. This is what collaborative, coordinated, responsible disclosure looks like.
    It was a pleasure to work with GitGuardian on this #PyPI #security investigation to help protect the global #Python #SupplyChain

    blog.gitguardian.com/hunting-l

    Also serves as a reminder to adopt Trusted Publishing whenever possible!
    docs.pypi.org/trusted-publishe