{"type":"rich","version":"1.0","provider_name":"Transistor","provider_url":"https://transistor.fm","author_name":"Daily Security Review","title":"Inside the July 2025 PyPI Phishing Scam: How Hackers Stole Developer Credentials","html":"<iframe width=\"100%\" height=\"180\" frameborder=\"no\" scrolling=\"no\" seamless src=\"https://share.transistor.fm/e/607f9a2c\"></iframe>","width":"100%","height":180,"duration":3257,"description":"In this episode, we investigate the growing cybersecurity storm targeting the Python Package Index (PyPI) — the backbone of Python’s software distribution ecosystem. A recent phishing campaign in July 2025 has developers on high alert, as attackers impersonated PyPI using a deceptive domain (pypj.org) to trick maintainers into handing over their credentials. Victims were directed to a convincing PyPI lookalike site where their credentials were stolen — and silently relayed to PyPI’s legitimate servers, creating the illusion of a normal login and delaying detection.\nBut phishing is just one front in a much larger battle. The open-source software supply chain is under siege, with malicious packages skyrocketing — over 512,000 discovered since late 2023, a 156% year-over-year increase. Attackers leverage typosquatting, dependency confusion, and data exfiltration techniques to compromise developers and enterprises alike. Malware buried in these packages has ranged from crypto miners and backdoors to credential stealers and PII exfiltration tools.\nKey issues we cover include:\nPyPI’s phishing threat response: how admins added warning banners and launched takedowns of the malicious infrastructure.\nThe critical role of Multi-Factor Authentication (MFA), now mandatory for PyPI accounts, in preventing account compromise.\nThe concept of Persistent Risk: why 80% of dependencies remain outdated for over a year, despite safer alternatives existing.\nHistoric lessons from Log4Shell, SolarWinds, and the XZ Utils incident, showing the escalating sophistication of supply chain attacks.\nWhy the AI revolution in phishing — with voice synthesis, deepfakes, and multi-channel deception — is raising the stakes for developers and organizations.\nPractical defenses, from Software Composition Analysis (SCA) tools in CI/CD pipelines to careful package reputation checks and strict credential hygiene.\nAs the market for AI-driven cybersecurity surges toward $93.75 billion by 2030, the fight for...","thumbnail_url":"https://img.transistorcdn.com/pL79_MJFeJHamQ_ztImsGmDSMdl27VMk_30TAkieujE/rs:fill:0:0:1/w:400/h:400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8yNzg5/ZjlhNzM5Y2M4Njli/NjkxNzgyODA2Nzhi/MDI2ZC5wbmc.webp","thumbnail_width":300,"thumbnail_height":300}