Skip to main content
News Directory 3
  • Business
  • Entertainment
  • Health
  • News
  • Sports
  • Tech
  • World
Menu
  • Business
  • Entertainment
  • Health
  • News
  • Sports
  • Tech
  • World
PyPI Blocks Domain Resurrection Attacks - Account Hijacking Prevention - News Directory 3

PyPI Blocks Domain Resurrection Attacks – Account Hijacking Prevention

August 19, 2025 Lisa Park Tech
News Context
At a glance
  • The Python Package Index (PyPI), the central repository for open-source Python software, is constantly under threat from malicious ⁣actors.
  • The core of the problem lies in⁣ how PyPI verifies account ownership.
  • To address this escalating threat,PyPI has implemented a new system to proactively identify and mitigate the risk of domain resurrection attacks.
Original source: bleepingcomputer.com

PyPI Bolsters security Against Account takeovers with Domain monitoring

Table of Contents

  • PyPI Bolsters security Against Account takeovers with Domain monitoring
    • The Growing Threat to the Python Ecosystem
    • How PyPI is Fighting Back
    • What This Means for ⁤Developers
    • Understanding domain Lifecycle Stages

Published August 19, 2025

The Growing Threat to the Python Ecosystem

The Python Package Index (PyPI), the central repository for open-source Python software, is constantly under threat from malicious ⁣actors. A notably insidious attack vector involves exploiting expired domain names linked to maintainer accounts. This allows attackers ⁢to hijack projects adn distribute compromised packages to the vast community of Python⁤ developers, product maintainers, and companies relying on the ecosystem.

What: New protections against “domain resurrection” attacks on PyPI.

Where: The Python Package Index (PyPI).

When: Measures ⁤implemented‍ in June ⁤2025, advancement began in April 2025.Why it matters: Prevents supply-chain attacks by securing maintainer accounts.What’s next: Users should enable two-factor authentication and add backup email addresses.

The core of the problem lies in⁣ how PyPI verifies account ownership. many project maintainers associate their ⁤accounts⁤ with email addresses tied to custom domain names. When these domains lapse and are re-registered by malicious parties, attackers can initiate password resets and gain control of the associated PyPI accounts. This⁢ isn’t a theoretical risk; the ‘ctx’ package was compromised in May 2022, demonstrating the real-world impact of this vulnerability. In that incident, attackers injected‍ code designed to steal Amazon Web Services (AWS) keys and ⁤credentials from‍ users of the package.

How PyPI is Fighting Back

To address this escalating threat,PyPI has implemented a new system to proactively identify and mitigate the risk of domain resurrection attacks. The platform now‍ regularly checks the status of domains associated with verified email addresses. This is achieved through integration with Domainr’s Status API, wich‍ provides information on a domain’s lifecycle stage – whether it’s active, in a grace period, undergoing redemption, or pending deletion.

Domain lifecycle stages
Domain lifecycle stages
Source: PyPI

When a domain enters a pre-expiration state (grace or redemption period), PyPI marks the associated email address as unverified. This prevents attackers from using password resets to hijack the account,even if they’ve successfully re-registered the domain. As the initial rollout ⁣in June 2025, over 1,800 email addresses have been flagged as unverified, demonstrating the prevalence of potentially vulnerable accounts.

What This Means for ⁤Developers

While this new system isn’t a perfect solution – other⁤ attack vectors still exist -⁣ it represents a notable step forward in securing the Python supply chain.it’s a ‍proactive defense,closing⁢ a critical window of opportunity for attackers. However, developers and package maintainers also have a crucial role to play in protecting their‍ accounts.

PyPI strongly recommends two key security measures:

  • Add a Backup ⁤Email: Associate a backup ⁢email address with ⁣your account that uses a non-custom domain (e.g., Gmail, Outlook). This ensures you can still recover your account even if your primary domain is ‍compromised.
  • Enable⁣ Two-Factor⁣ Authentication (2FA): 2FA adds an extra layer of security, requiring a code from your authenticator app along‍ with your password.

– lisapark

The move by pypi is a welcome response to a growing and⁤ complex threat landscape. Supply chain attacks are becoming increasingly common, and⁣ securing the foundations of open-source software is paramount. While the ⁤Domainr integration is a smart technical⁢ solution, the ultimate security of the ecosystem relies on the vigilance of individual developers and ⁤maintainers. Proactive security measures, like ⁢those recommended by PyPI, are no longer optional – they are essential.

Understanding domain Lifecycle Stages

The effectiveness of PyPI’s new system hinges on understanding the⁣ different stages of a domain’s lifecycle. Here’s a breakdown:

Stage Description PyPI Action
Active Domain is registered and functioning normally. Email⁣ address remains verified.
Grace Period A short period after expiration where the domain can be renewed at the standard rate. Email address marked as unverified.
Redemption Period A longer period⁢ after the grace period, with a higher renewal fee. Email address marked as unverified.
Pending Deletion the domain is scheduled for deletion. Email address marked as unverified.

This article provides information about recent security enhancements to the python Package Index (PyPI) as of ⁢August 19, 2025. For the latest updates and security recommendations, please refer to the official PyPI⁢ blog.

Share this:

  • Share on Facebook (Opens in new window) Facebook
  • Share on X (Opens in new window) X

Related reading

  • TMOG monitors system performance on Windows, macOS and Linux
  • Macon Family Preserves Century of Black History at Historic Home

Related

Search:

News Directory 3

News Directory 3 catalogs US newspapers, news services, newsstands and digital news outlets across all 50 states. Browse local publishers by city, state, or topic, and follow current headlines linked back to their original sources.

Quick Links

  • Disclaimer
  • Terms and Conditions
  • About Us
  • Advertising Policy
  • Contact Us
  • Cookie Policy
  • Editorial Guidelines
  • Privacy Policy

Browse by State

  • Alabama
  • Alaska
  • Arizona
  • Arkansas
  • California
  • Colorado

© 2026 News Directory 3. All rights reserved.
For contact, advertising, copyright, issues email: office@newsdirectory3.com