Python devs targeted with dangerous phishing attacks – here’s how to stay safe




  • Developers who published projects on PyPI with their email in package metadata are being targeted
  • They are asked to “verify” their email address with a fake PyPI platform
  • The “verification” process relays login credentials to attackers

Python developers are being targeted with dangerous phishing attacks, The Python Software Foundation (PSF) has warned .

PSF said threat actors were actively targeting developers who have published projects on PyPI with their email in package metadata. These developers are receiving emails asking them to “verify” their email address on the platform, providing a link to do so.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *