Popular LiteLLM PyPI package backdoored to steal credentials, auth tokens
(bleepingcomputer.com)
1.
2.
Popular LiteLLM PyPI package compromised in TeamPCP supply chain attack
(bleepingcomputer.com)
3.
Tell HN: Litellm 1.82.7 and 1.82.8 on PyPI are compromised
(news.ycombinator.com)
4.
Pyodide: a Python distribution based on WebAssembly
(news.ycombinator.com)
5.
Okmain: How to pick an OK main colour of an image
(news.ycombinator.com)
6.
PyPI in 2025: A Year in Review
(news.ycombinator.com)
7.
Blog: PyPI in 2025: A Year in Review
(news.ycombinator.com)
8.
9.
PyPI urges users to reset credentials after new phishing attacks
(bleepingcomputer.com)
10.
PyPI Blog: Token Exfiltration Campaign via GitHub Actions Workflows
(news.ycombinator.com)
11.
PyPI invalidates tokens stolen in GhostAction supply chain attack
(bleepingcomputer.com)
12.
PyPI now blocks domain resurrection attacks used for hijacking accounts
(bleepingcomputer.com)
13.
PyPI Preventing Domain Resurrection Attacks
(news.ycombinator.com)
14.
Preventing ZIP parser confusion attacks on Python package installers
(news.ycombinator.com)
15.
PyPI: Preventing ZIP parser confusion attacks on Python package installers
(news.ycombinator.com)
16.
Hackers target Python devs in phishing attacks using fake PyPI site
(bleepingcomputer.com)
17.
PyPI Prohibits inbox.ru email domain registrations
(news.ycombinator.com)