Target Industry

The campaign appears to be indiscriminate, opportunistically targeting Python developers involved in open-source projects.

Overview

An advanced phishing attack is targeting developers who maintain packages on the Python Package Index (PyPI). Threat actors are using a combination of domain spoofing, domain confusion (the use of lookalike or misleading domain names), and social engineering techniques to deceive victims into revealing their login credentials. The threat actors are leveraging professional-looking websites and urgent messaging to create a false sense of legitimacy, making the campaign particularly effective even against experienced developers.

Impact

The impact of phishing attacks targeting PyPI developers on organisations can be significant and far-reaching. These attacks could result in supply chain compromise, credential theft, and unauthorised access, as well as reputational damage and operational disruption.

Exploitation

Fake emails are being sent, pretending to be from PyPI, urging users to verify their email to avoid account suspension. The threat of suspension is used to create a sense of urgency. Users are then directed to a mirror website that closely replicates PyPI’s login interface, including logos and styling. The threat actors harvest the credentials entered on the fake site.

Indicator of Compromise

The malicious domain users are being directed to is pypi-mirror[.]org. PyPI’s security team is working with domain registrars and CDNs to take down the malicious site.

Containment, Mitigations & Remediations

It is highly recommended to strengthen account security by enabling multi-factor authentication and using strong, unique passwords. Employees should be educated about phishing attacks and safe email practices. Use tools to scan and monitor Python packages for integrity and unexpected changes. Implement dependency pinning (locking software dependencies to specific versions to prevent unexpected updates or changes) and verify package sources before applying updates.

Threat Landscape

PyPI is the default repository for Python packages accessed via pip, the standard Python package installer. It supports millions of developers globally, underpinning a wide range of applications from data science to web development and machine learning. This campaign underscores the importance of monitoring domain registrations and verifying the authenticity of email communications.

Threat Group

At the time of writing, no specific threat group has been publicly attributed to the phishing campaign targeting PyPI maintainers.

TTPS

Further Information

New Phishing Attack Targeting PyPI Maintainers to Steal Login Credentials

Intelligence Terminology Yardstick

The threat report uses pre-defined language found within the Intelligence Terminology Yardstick to express the likelihood of events.

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content