PyPI restored after weekend attack

By
Follow google news

Sign-ups, uploads halted for 29 hours.

The PyPI Python code repository was restored earlier this morning, following a weekend outage because it was under attack.

PyPI restored after weekend attack

Sign-up and package upload functions were blocked during the outage.

A status notification provides little detail, but it appears an automated attack was the possible source.

“The volume of malicious users and malicious projects being created on the index in the past week has outpaced our ability to respond to it in a timely fashion, especially with multiple PyPI administrators on leave," the repository's overseers said.

The outage lasted around 29 hours.

In January, the repository suffered a supply-chain attack to the package torchtriton, part of the Triton language and compiler used for writing custom deep-learning primitives.

Previous typo-squat supply-chain attacks against PyPI include one in May 2022, in which PyPI ctx and a fork of PHP phpass were targeted in attacks designed to steal AWS credentials; while in 2017, Slovakia’s CERT discovered 10 bogus packages on the site.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

The BoM has finally tamed SSL

The BoM has finally tamed SSL

Scores of Australian Cisco devices remain BADCANDY infected

Scores of Australian Cisco devices remain BADCANDY infected

US prosecutors say cyber security pros ran cybercrime operation

US prosecutors say cyber security pros ran cybercrime operation

Australia and US impose sanctions on North Korean cyber ops

Australia and US impose sanctions on North Korean cyber ops

Log In

  |  Forgot your password?