frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Open in hackernews

PyPI Users Email Phishing Attack

https://blog.pypi.org/posts/2025-07-28-pypi-phishing-attack/
2•miketheman•6h ago

Comments

miketheman•6h ago
There is an active phishing attack targeting PyPI users.

• Threat: Emails from noreply@pypj.org (with a 'j') link to a fake login page.

• Action: Do not click any links. If you already did, change your PyPI password ASAP.

• Note: PyPI itself has not been breached.

zahlman•3h ago
Ah, I was beaten to it...

The Python Package Index (PyPI), a central repository of third-party Python packages, is now seeing what appears to be a fairly wide-scale phishing attack. The attackers are squatting on "pypj.org" — a plausible typo, but more likely chosen to visually resemble "pypi.org" in a browser address bar.

This was first reported by Python core developer Ethan Furman (@stoneleaf), who was personally targeted, on the Python Discourse forum[1]; the thread title was made more authoritative after it was confirmed that the attack was not a one-off. There is some speculation in the thread that the attack may be targeting developers who have, or ever have had, a package identified as "critical". (Previously, PyPI rolled out a 2FA requirement for owners/maintainers of the most commonly downloaded "critical" packages, along with a security key giveaway[2]; in 2023 they announced[3] that 2FA would be required for all accounts starting at the beginning of 2024, and made good on that[4]. Amusingly, this status designation once took another core developer by surprise[5].)

PyPI staff are well aware of the attack (hence the linked blog post) and have also added a warning banner to the main https://pypi.org site.

[1]: https://discuss.python.org/t/pypi-org-phishing-attack/100267

[2]: https://pypi.org/security-key-giveaway/

[3]: https://blog.pypi.org/posts/2023-05-25-securing-pypi-with-2f...

[4]: https://blog.pypi.org/posts/2024-01-01-2fa-enforced/

[5]: https://discuss.python.org/t/a-defunct-project-of-mine-has-b...

Brutal punishments meted out to Russian soldiers unwilling to fight for Putin

https://www.cnn.com/2025/07/28/europe/russia-deserters-ukraine-war-intl
1•breve•53s ago•0 comments

Google can review or read all user communications, including private messages

https://tosdr.org/en/service/217
1•JXL34•56s ago•1 comments

The sound of clapping, explained by physics

https://www.sciencenews.org/article/sound-clapping-physics-explained
1•austinallegro•2m ago•0 comments

Be thoughtful when retiring old domain names

1•Pine_Mushroom•3m ago•0 comments

Show HN: I added webhook response support for MCP tool calls in asyncmcp

https://github.com/bh-rat/asyncmcp/releases/tag/v0.2.0
1•bharatgel•3m ago•0 comments

The Burnout Society

http://hypercritic.org/collection/byung-chul-han-the-burnout-society-against-freedom-2010-review
1•rawgabbit•6m ago•0 comments

Certificate authorities and DNS replacement to get a alternative internet?

1•outfoxsemillc•6m ago•1 comments

Show HN: New way to validate your LLM webapp idea and earn on token margins

https://codeplusequalsai.com
1•cryptoz•6m ago•0 comments

I Tried to Replace Myself with ChatGPT in My English Classroom

https://lithub.com/what-happened-when-i-tried-to-replace-myself-with-chatgpt-in-my-english-classroom/
1•mrjaeger•7m ago•0 comments

Ollama.com A website to download LLMs and try AI quick and easy

https://ollama.com/
1•gitprolinux•9m ago•0 comments

AMD teams contributing to the llama.cpp codebase

https://github.com/ggml-org/llama.cpp/pull/14624
1•gzer0•16m ago•0 comments

Nasubi – a real life "Truman Show"

https://en.wikipedia.org/wiki/Nasubi
1•ColinWright•21m ago•0 comments

Harnessing Noncanonical Proteins for Next-Gen Drug Discovery and Diagnosis

https://wires.onlinelibrary.wiley.com/doi/10.1002/wsbm.70001
1•PaulHoule•21m ago•0 comments

Submarines and Foolkillers

https://chicagology.com/harbor/foolkiller/
1•ilamont•22m ago•0 comments

Approximating Reality with CSS Linear()

https://blog.nordcraft.com/approximating-reality-with-css-linear
2•AndreasMoeller•24m ago•0 comments

The First Realtime AI Prompt Management App

https://www.getsnippets.ai/
1•artluko•24m ago•1 comments

The Useless UseCallback

https://tkdodo.eu/blog/the-useless-use-callback
2•0xedb•25m ago•0 comments

DeltaNet Explained

https://sustcsonglin.github.io/blog/2024/deltanet-1/
1•jxmorris12•27m ago•0 comments

Cranelift compiler efficiency, CFGs, and a branch peephole optimizer

https://cfallin.org/blog/2021/01/22/cranelift-isel-2/
1•fanf2•27m ago•0 comments

Origin of "There are only two hard things in Computer Science" quote (2014)

https://skeptics.stackexchange.com/questions/19836/has-phil-karlton-ever-said-there-are-only-two-hard-things-in-computer-science
2•nailer•27m ago•0 comments

Rewriting Training Data Improved Kimi 2's Performance

https://www.dbreunig.com/2025/07/27/kimi-applies-rephrasing-to-pre-training-data.html
1•dbreunig•27m ago•0 comments

Virtual Power Plants: Reimagining the Grid for the 21st Century

https://www.utilitydive.com/news/reimagining-the-grid-for-the-21st-century-with-virtual-power-plants/754077/
3•bdev12345•33m ago•0 comments

Auto-generate Linear tasks from meeting transcripts

https://www.snaplinear.app/demo
1•jonahkpump•35m ago•1 comments

We Faked the Moon Landing

https://rumble.com/v60ykdw-how-we-faked-the-moon-landing-with-bart-sibrel-candace-ep-124.html
1•throwaway-153•36m ago•2 comments

Hostile Alien Object Speeds to Earth, Harvard Scientist Says It's Hiding

https://www.ibtimes.co.uk/hostile-alien-object-hurtling-towards-earth-12-mile-entity-deliberately-hiding-detection-1739448
2•handfuloflight•38m ago•1 comments

Founders and Recruiters, Beware

https://twitter.com/pranay01/status/1949896185462083787
3•pranay01•41m ago•0 comments

Throwing AI at Developers Won't Fix Their Problems

https://www.aviator.co/blog/throwing-ai-at-developers-wont-fix-their-problems/
1•tonkkatonka•41m ago•1 comments

Show HN: KrackTheKode – Daily number code-breaking game

https://krackthekode.pyrrho.dev
1•Pyrrho3•43m ago•0 comments

Text-audio foundation model from Boson AI

https://github.com/boson-ai/higgs-audio
1•chaosprint•44m ago•0 comments

Jetson Thor – Advanced AI for Physical Robotics

https://www.nvidia.com/en-us/autonomous-machines/embedded-systems/jetson-thor/
1•gnabgib•45m ago•0 comments