The Python Package Index (PyPI) repository’s maintainers have warned users of a persistent phishing attempt that aims to divert them to fraudulent PyPI websites.
The attack entails sending emails from the email address noreply@pypj[.]org with the subject line “[PyPI] Email verification” (notice that the domain is not “pypi[.]org”).
Mike Fiedler, the administrator of PyPI, stated in a post on Monday that this is a phishing attempt that takes advantage of users’ faith in PyPI rather than a security breach of PyPI itself.
The emails direct users to click on a link to confirm their email address, which takes them to a phishing site that mimics PyPI and is set up to steal their login credentials.
However, in a devious turn of events, after the login credentials are entered on the fraudulent website, the request is forwarded to the authentic PyPI website read more about PyPI Warns of Ongoing Phishing Campaign Using Fake Verification Emails and Lookalike Domain.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
