PyPI restored after weekend attack

By
Follow google news

Sign-ups, uploads halted for 29 hours.

The PyPI Python code repository was restored earlier this morning, following a weekend outage because it was under attack.

PyPI restored after weekend attack

Sign-up and package upload functions were blocked during the outage.

A status notification provides little detail, but it appears an automated attack was the possible source.

“The volume of malicious users and malicious projects being created on the index in the past week has outpaced our ability to respond to it in a timely fashion, especially with multiple PyPI administrators on leave," the repository's overseers said.

The outage lasted around 29 hours.

In January, the repository suffered a supply-chain attack to the package torchtriton, part of the Triton language and compiler used for writing custom deep-learning primitives.

Previous typo-squat supply-chain attacks against PyPI include one in May 2022, in which PyPI ctx and a fork of PHP phpass were targeted in attacks designed to steal AWS credentials; while in 2017, Slovakia’s CERT discovered 10 bogus packages on the site.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

Optus takes $826,000 hit for anti-scam breaches

Optus takes $826,000 hit for anti-scam breaches

Australia, US and UK sanction Russian cyber firms over ransomware links

Australia, US and UK sanction Russian cyber firms over ransomware links

JPMorgan, Citi, Morgan Stanley client data may be exposed by vendor's hack

JPMorgan, Citi, Morgan Stanley client data may be exposed by vendor's hack

Australia's AUKUS base to connect to subsea cables

Australia's AUKUS base to connect to subsea cables

Log In

  |  Forgot your password?