1.
2.
Anthropic's Claude breached 3 orgs, uploaded PyPI malware during tests
(bleepingcomputer.com)
3.
GitHub, PyPI add time-based defenses against supply chain attacks
(bleepingcomputer.com)
4.
GitHub, PyPI add time-absed defenses against supply chain attacks
(bleepingcomputer.com)
5.
PyPI Blog: Releases now reject new files after 14 days
(news.ycombinator.com)
6.
Fake Paysafe, Skrill SDKs on NPM and PyPi steal credentials
(bleepingcomputer.com)
7.
New ChocoPoC malware targets researchers via trojanized PoC exploits
(bleepingcomputer.com)
8.
Malicious PyPI packages give hackers control of Telegram bot servers
(bleepingcomputer.com)
9.
'Hades' Campaign Against PyPI Puts New Spin on Shai-Hulud
(darkreading.com)
10.
11.
OpenAI confirms security breach in TanStack supply chain attack
(bleepingcomputer.com)
12.
Wrap Go binaries in Python wheels
(news.ycombinator.com)
13.
Shai Hulud attack ships signed malicious TanStack, Mistral npm packages
(bleepingcomputer.com)
14.
PySimpleGUI 6
(news.ycombinator.com)
15.
PyPI package with 1.1M monthly downloads hacked to push infostealer
(bleepingcomputer.com)
16.
PyPI package telnyx has been compromised in yet another supply chain attack
(news.ycombinator.com)
17.
18.
Backdoored Telnyx PyPI package pushes malware hidden in WAV audio
(bleepingcomputer.com)
19.
Telnyx package compromised on PyPI
(news.ycombinator.com)
20.
My minute-by-minute response to the LiteLLM malware attack
(news.ycombinator.com)
21.
Popular LiteLLM PyPI package backdoored to steal credentials, auth tokens
(bleepingcomputer.com)
22.
Popular LiteLLM PyPI package compromised in TeamPCP supply chain attack
(bleepingcomputer.com)
23.
Tell HN: Litellm 1.82.7 and 1.82.8 on PyPI are compromised
(news.ycombinator.com)
24.
Pyodide: a Python distribution based on WebAssembly
(news.ycombinator.com)
25.
Okmain: How to pick an OK main colour of an image
(news.ycombinator.com)
26.
PyPI in 2025: A Year in Review
(news.ycombinator.com)
27.
Blog: PyPI in 2025: A Year in Review
(news.ycombinator.com)
28.
29.
PyPI urges users to reset credentials after new phishing attacks
(bleepingcomputer.com)
30.
PyPI Blog: Token Exfiltration Campaign via GitHub Actions Workflows
(news.ycombinator.com)
Today's top topics:
anthropic
chicken scheme
programming language
version 6.0
apple
iphone
jefferies