Target Industry
The campaign appears to be indiscriminate, opportunistically targeting Python developers involved in open-source projects.
Overview
An advanced phishing attack is targeting developers who maintain packages on the Python Package Index (PyPI). Threat actors are using a combination of domain spoofing, domain confusion (the use of lookalike or misleading domain names), and social engineering techniques to deceive victims into revealing their login credentials. The threat actors are leveraging professional-looking websites and urgent messaging to create a false sense of legitimacy, making the campaign particularly effective even against experienced developers.
Impact
The impact of phishing attacks targeting PyPI developers on organisations can be significant and far-reaching. These attacks could result in supply chain compromise, credential theft, and unauthorised access, as well as reputational damage and operational disruption.
Exploitation
Fake emails are being sent, pretending to be from PyPI, urging users to verify their email to avoid account suspension. The threat of suspension is used to create a sense of urgency. Users are then directed to a mirror website that closely replicates PyPI’s login interface, including logos and styling. The threat actors harvest the credentials entered on the fake site.
Indicator of Compromise
The malicious domain users are being directed to is pypi-mirror[.]org. PyPI’s security team is working with domain registrars and CDNs to take down the malicious site.
Containment, Mitigations & Remediations
It is highly recommended to strengthen account security by enabling multi-factor authentication and using strong, unique passwords. Employees should be educated about phishing attacks and safe email practices. Use tools to scan and monitor Python packages for integrity and unexpected changes. Implement dependency pinning (locking software dependencies to specific versions to prevent unexpected updates or changes) and verify package sources before applying updates.
Threat Landscape
PyPI is the default repository for Python packages accessed via pip, the standard Python package installer. It supports millions of developers globally, underpinning a wide range of applications from data science to web development and machine learning. This campaign underscores the importance of monitoring domain registrations and verifying the authenticity of email communications.
Threat Group
At the time of writing, no specific threat group has been publicly attributed to the phishing campaign targeting PyPI maintainers.
TTPS
Further Information
New Phishing Attack Targeting PyPI Maintainers to Steal Login Credentials
Intelligence Terminology Yardstick

The threat report uses pre-defined language found within the Intelligence Terminology Yardstick to express the likelihood of events.











