{"type":"rich","version":"1.0","provider_name":"Transistor","provider_url":"https://transistor.fm","author_name":"Daily Security Review","title":"PyPI Cracks Down on Domain Expiration Attacks to Protect Python Packages","html":"<iframe width=\"100%\" height=\"180\" frameborder=\"no\" scrolling=\"no\" seamless src=\"https://share.transistor.fm/e/800d5972\"></iframe>","width":"100%","height":180,"duration":2701,"description":"The Python Package Index (PyPI), the backbone of the global Python ecosystem, has rolled out new security safeguards aimed at stopping a dangerous form of supply-chain attack: domain resurrection attacks. These attacks exploit a subtle but devastating weakness—when a maintainer’s email domain expires, attackers can re-register it, hijack the email, and reset the maintainer’s PyPI account password. With that access, malicious actors could inject harmful code into widely used Python packages, creating ripple effects across software projects worldwide.\nTo address this, PyPI has introduced a preventive control: email addresses linked to expired or expiring domains are now marked unverified and immediately blocked from being used in account recovery or password resets. This closes a key loophole that attackers have previously exploited, including a 2022 incident where the ctx package was hijacked and seeded with rogue code. Since June 2025, PyPI has already flagged over 1,800 at-risk email addresses by tracking domain registration states with the help of Fastly’s monitoring tools.\nWhile this marks a significant improvement in the security posture of the platform, PyPI warns that the responsibility is shared. Maintainers are urged to:\nEnable Two-Factor Authentication (2FA) on their accounts, using multiple authentication methods and storing recovery codes safely.\nAdd backup email addresses tied to trusted providers like Gmail or Outlook, ensuring they don’t rely solely on custom domains that may expire.\nThis move comes amid a broader wave of software supply-chain threats, where attackers increasingly target open-source dependencies as stepping stones into enterprise systems. From SolarWinds to Log4Shell to the near-miss XZ Utils backdoor, the software world has learned that the open-source ecosystem is both powerful and highly vulnerable. In fact, malicious open-source packages have surged by over 150% year-over-year, and tools like PyPI are under constant assault from...","thumbnail_url":"https://img.transistorcdn.com/pL79_MJFeJHamQ_ztImsGmDSMdl27VMk_30TAkieujE/rs:fill:0:0:1/w:400/h:400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8yNzg5/ZjlhNzM5Y2M4Njli/NjkxNzgyODA2Nzhi/MDI2ZC5wbmc.webp","thumbnail_width":300,"thumbnail_height":300}