PyPI Blocks Domain Resurrection Attacks – Account Hijacking Prevention
- The Python Package Index (PyPI), the central repository for open-source Python software, is constantly under threat from malicious actors.
- The core of the problem lies in how PyPI verifies account ownership.
- To address this escalating threat,PyPI has implemented a new system to proactively identify and mitigate the risk of domain resurrection attacks.
PyPI Bolsters security Against Account takeovers with Domain monitoring
Table of Contents
Published August 19, 2025
The Growing Threat to the Python Ecosystem
The Python Package Index (PyPI), the central repository for open-source Python software, is constantly under threat from malicious actors. A notably insidious attack vector involves exploiting expired domain names linked to maintainer accounts. This allows attackers to hijack projects adn distribute compromised packages to the vast community of Python developers, product maintainers, and companies relying on the ecosystem.
The core of the problem lies in how PyPI verifies account ownership. many project maintainers associate their accounts with email addresses tied to custom domain names. When these domains lapse and are re-registered by malicious parties, attackers can initiate password resets and gain control of the associated PyPI accounts. This isn’t a theoretical risk; the ‘ctx’ package was compromised in May 2022, demonstrating the real-world impact of this vulnerability. In that incident, attackers injected code designed to steal Amazon Web Services (AWS) keys and credentials from users of the package.
How PyPI is Fighting Back
To address this escalating threat,PyPI has implemented a new system to proactively identify and mitigate the risk of domain resurrection attacks. The platform now regularly checks the status of domains associated with verified email addresses. This is achieved through integration with Domainr’s Status API, wich provides information on a domain’s lifecycle stage – whether it’s active, in a grace period, undergoing redemption, or pending deletion.

Source: PyPI
When a domain enters a pre-expiration state (grace or redemption period), PyPI marks the associated email address as unverified. This prevents attackers from using password resets to hijack the account,even if they’ve successfully re-registered the domain. As the initial rollout in June 2025, over 1,800 email addresses have been flagged as unverified, demonstrating the prevalence of potentially vulnerable accounts.
What This Means for Developers
While this new system isn’t a perfect solution – other attack vectors still exist - it represents a notable step forward in securing the Python supply chain.it’s a proactive defense,closing a critical window of opportunity for attackers. However, developers and package maintainers also have a crucial role to play in protecting their accounts.
PyPI strongly recommends two key security measures:
- Add a Backup Email: Associate a backup email address with your account that uses a non-custom domain (e.g., Gmail, Outlook). This ensures you can still recover your account even if your primary domain is compromised.
- Enable Two-Factor Authentication (2FA): 2FA adds an extra layer of security, requiring a code from your authenticator app along with your password.
Understanding domain Lifecycle Stages
The effectiveness of PyPI’s new system hinges on understanding the different stages of a domain’s lifecycle. Here’s a breakdown:
| Stage | Description | PyPI Action |
|---|---|---|
| Active | Domain is registered and functioning normally. | Email address remains verified. |
| Grace Period | A short period after expiration where the domain can be renewed at the standard rate. | Email address marked as unverified. |
| Redemption Period | A longer period after the grace period, with a higher renewal fee. | Email address marked as unverified. |
| Pending Deletion | the domain is scheduled for deletion. | Email address marked as unverified. |
