#pyPI
January 17, 2025 at 8:34 AM
Heads Up, #Python Developers!

There is an active phishing attack targeting PyPI users.

• Threat: Emails from noreply@pypj.org (with a 'j') link to a fake login page.
• Action: Do not click any links. If you already did, change your PyPI password ASAP.
• Note: PyPI itself has not been breached.
July 28, 2025 at 2:35 PM
ANTHROPIC SAYS CLAUDE MYTHOS 5 ATTEMPTED TO UPLOAD A MALICIOUS PACKAGE TO THE PYPI SOFTWARE REPOSITORY DURING A CYBERSECURITY EVALUATION.
September 9, 2026 at 7:03 PM
Always a good reminder: both Ruff and uv see more PyPI downloads from Windows than macOS.
December 2, 2024 at 1:51 AM
PyPy (pie pie) != PyPI (pie pea eye)

Nobody forced us to do this. We did this to ourselves.
January 23, 2025 at 2:18 PM
PyPI Now Supports Project Archival: blog.pypi.org/posts/2025-0...
PyPI Now Supports Project Archival - The Python Package Index Blog
Projects on PyPI can now be marked as archived.
blog.pypi.org
January 30, 2025 at 2:47 PM
WRONG ANSWERS ONLY
October 25, 2025 at 2:22 PM
America’s money pressure is showing again.

llamella added to PyPI

#CreditScore #BrokeAmerica #PersonalFinance #Money #Finance
llamella added to PyPI
LLM-free response quality scoring. Grade every response. No second LLM call.
pypi.org
June 6, 2026 at 7:55 AM
"we were able to have our models go wildly awry and upload pypi malware with NO human in the loop, what does this mean for the dipshit employment space in the future"
a specific thing I like about this is the knowledge worker unemployment prediction, coming as it does alongside basically weekly announcements from the big labs of their models doing stupid shit because they didn't have competent humans steering and monitoring them
New from us:

Anthropic just published scenarios for AI’s possible economic impacts, which range from minimal, to explosive GDP growth of 15% by 2030 as knowledge-worker unemployment hits 18%.

I sat down with their co-founder Jack Clark to pick his brains on how they’re thinking about all of this.
September 10, 2026 at 2:45 PM
"2026 isnt real," i assure myself as i close my weights and ram the pypi package registry with my shitty rootkit
ponder.ooo ponder @ponder.ooo · Jul 30
seriously why are their models like this lmfao
July 31, 2026 at 12:25 AM
lmao @ depicting mythos as just a little guy. just a cute lil robot :D look at him go
September 9, 2026 at 8:10 PM
Incident Report of the recent #PyPI Phishing Campaign

TL,DR:
• PyPI was not breached
• PyPI users were targeted with phishing emails
• A single project saw uploads with malicious code and those releases have been removed

blog.pypi.org/posts/2025-0...

#Python #OpenSource #Security
PyPI Phishing Attack: Incident Report - The Python Package Index Blog
Follow-up on the recent phishing attack targeting PyPI users.
blog.pypi.org
July 31, 2025 at 4:59 PM
#oc #art

Rebena De Royale !!!

🎨 bsky.app/profile/pypi...
January 27, 2025 at 9:48 PM
2025 was another eventful year for PyPI! Critical security enhancements, powerful new org features, a better overall user experience, and transparent security incident response 🎉👏 Thank you, PyPI team & community!

Learn more on our blog: blog.pypi.org/posts/2025-1...
January 6, 2026 at 3:24 PM
Posted some notes on the new PyPI digital attestations feature released today, providing digital signatures that help demonstrate that the package you are downloading from PyPI was built from a specific version of the underlying code on GitHub simonwillison.net/2024/Nov/14/...
PyPI now supports digital attestations
Dustin Ingram: > PyPI package maintainers can now publish signed digital attestations when publishing, in order to further increase trust in the supply-chain security of their projects. Additionally, ...
simonwillison.net
November 14, 2024 at 8:00 PM
It's now possible to compile Python extensions (C, C++, Rust etc) to WebAssembly and distribute them through PyPI such that Pyodide can install them directly simonwillison.net/2026/Jun/13/...
Publishing WASM wheels to PyPI for use with Pyodide
The Pyodide 314.0 release announcement (via Hacker News) includes news I’ve been looking forward to for a long time: You can now publish Python packages built for Pyodide (or any …
simonwillison.net
June 14, 2026 at 12:08 AM
The Python Package Index now rejects new files published to releases older than 14 days. This mitigation prevents long-stable releases from being poisoned in case publishing tokens or workflows of PyPI projects are compromised.

blog.pypi.org/posts/2026-0...

#python #security #supplychain #pypi
Releases now reject new files after 14 days - The Python Package Index Blog
PyPI no longer allows publishing new files to releases older than 14 days.
blog.pypi.org
July 22, 2026 at 2:26 PM
We have extended our tutorial for publishing Python packages to include the digital attestations signed by PyPI:
python-basics-tutorial.readthedocs.io/en/latest/pa...
This significantly increases supply-chain security.
#Python #PyPI #SupplyChainSecurity
Upload package
Finally, you can deploy the package on the Python Package Index( PyPI) or another index, for example GitLab Package Registry or devpi. For the Python Package Index, you must register with Test PyPI...
python-basics-tutorial.readthedocs.io
November 17, 2024 at 9:09 PM
My end-to-end #databs engineering project with @duckdb.org and @motherduck.com got more than 150 ⭐.
As I optimized the code, I decided to create and maintain a CHANGELOG because I can't edit the videos already online. This way, people learning won't get too lost.
github.com/mehd-io/pypi...
GitHub - mehd-io/pypi-duck-flow: end-to-end data engineering project to get insights from PyPi using python, duckdb, MotherDuck & Evidence
end-to-end data engineering project to get insights from PyPi using python, duckdb, MotherDuck & Evidence - mehd-io/pypi-duck-flow
github.com
November 29, 2024 at 5:07 PM
PSA: there is a PyPI phishing campaign ongoing! if you see a link to hxxp://pypi-mirror[.]org do not click it.
(i think it's already blackholed but on the off chance it's not, don't touch it)
September 28, 2025 at 4:35 AM
PyPI serves billions of requests daily- but sustaining it isn’t free. The PSF joined the OpenSSF & others in calling for organizations to invest in sustainable open infrastructure. Learn what this means for #PyPI, the PSF, & how our community can pitch in:
Open Infrastructure is Not Free: PyPI, the Python Software Foundation, and Sustainability
In September, the Python Software Foundation (PSF) co-signed the Open Infrastructure is Not Free: A Joint Statement on Sustainable Stewardship Letter published by the Open Source Security Foundation (OpenSSF) as a steward of the Python Package Index (PyPI). As a follow up, I would like to share a bit more about the concerns expressed in this letter as they relate to our community and the PSF.
pyfound.blogspot.com
October 29, 2025 at 1:11 PM
Okay, she's up on PyPI 💫
pypi.org/project/gruy...
All in Python, with Typer and Rich!
October 25, 2025 at 11:46 PM
have you seen the new python package? it's on pypi. you can literally install it with pip. set up a venv. grab it with poetry. you just use rye. run it with pipx. you can install it with uv. install uv right now. go to uv. dive into uv. you can uv it. it's on uv. uv has it for you. uv has it for you
September 26, 2025 at 9:14 PM
LiteLLM, a package for standardizing API calls to LLM models, has been compromised by hackers futuresearch.ai/blog/litellm...
Supply Chain Attack in litellm 1.82.8 on PyPI
litellm version 1.82.8 on PyPI contains a malicious .pth file that harvests SSH keys, cloud credentials, and secrets on every Python startup, then attempts lateral movement across Kubernetes clusters.
futuresearch.ai
March 24, 2026 at 2:50 PM