PyPI restored after weekend attack

By
Follow google news

Sign-ups, uploads halted for 29 hours.

The PyPI Python code repository was restored earlier this morning, following a weekend outage because it was under attack.

PyPI restored after weekend attack

Sign-up and package upload functions were blocked during the outage.

A status notification provides little detail, but it appears an automated attack was the possible source.

“The volume of malicious users and malicious projects being created on the index in the past week has outpaced our ability to respond to it in a timely fashion, especially with multiple PyPI administrators on leave," the repository's overseers said.

The outage lasted around 29 hours.

In January, the repository suffered a supply-chain attack to the package torchtriton, part of the Triton language and compiler used for writing custom deep-learning primitives.

Previous typo-squat supply-chain attacks against PyPI include one in May 2022, in which PyPI ctx and a fork of PHP phpass were targeted in attacks designed to steal AWS credentials; while in 2017, Slovakia’s CERT discovered 10 bogus packages on the site.

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

US medical device maker Stryker's Microsoft environment attacked

US medical device maker Stryker's Microsoft environment attacked

CBA builds two AI agents to boost cyber defences

CBA builds two AI agents to boost cyber defences

CBA chief impersonated in global investment fraud on Facebook

CBA chief impersonated in global investment fraud on Facebook

Poor WA gov M365 security led to $71k theft and children's data breached

Poor WA gov M365 security led to $71k theft and children's data breached

Log In

  |  Forgot your password?