
A series of sophisticated supply chain cyberattacks targeted major platforms like GitHub and PyPI, affecting thousands of users. Hackers compromised GitHub and PyPI accounts using fake Python infrastructure, impacting large communities like Top.gg and Discord bot repositories.
PyPI Halts Sign-Ups Amid Surge of Malicious Package Uploads Targeting Developers https://t.co/3LURy5RLtf
⚠️ 👩💻 PyPI under attack...again. 🐍 Python's Package Index temporarily shut down new user sign-ups and project creation due to a surge of malicious typosquatting attempts. Learn more: https://t.co/VtO3wmqvve #Malware aimed to snag #cryptocurrency wallets and more. #DevSecOps
An unnamed #ThreatActor used fake #python infrastructure to poison multiple #GitHub code repositories, including one dedicated to @Discord bot discovery platform Top[.]gg. ☠️ https://t.co/3CE7TCQd57
