The Python Package Index (PyPI) has implemented new security measures to mitigate supply chain attacks by blocking over 1,800 email addresses associated with expired domains. This move addresses a vulnerability where attackers could hijack Python packages by registering expired domains to intercept account reset emails. While this enhancement improves account security, it is not a comprehensive solution to all supply chain threats. Separately, the Seamless Community Discord experienced a brief security compromise but has since been secured and restored to normal operation.
PyPI’s package manager has now started checking for expired domains. https://t.co/Wd4yCRpHIC
Notes on PyPI's new protection against domain resurrection attacks, where an attacker registers an expired domain in order to gain access to account reset emails https://t.co/9T6nsBMEax
Hi Seamless Supporters, Seamless’s Community Discord was briefly compromised overnight. Fortunately, the issue has been resolved and the server is now secure and operational. Thank you to everyone for your swift response and attention to this matter! Back to building.