Skip to content

project

PyPI

The official third-party software repository for the Python programming language, hosting packages that developers install via pip.

Known aliases

  • pypi.org
  • PyPI software registry
  • Python Package Index

Relationships

No evidence-backed relationships are recorded.

Current stories

build1 publisher

A static denylist stopped one more prompt injection than no protection in a coding-agent study

Bouras, Dai and Mechtaev found a static denylist let 46 of 75 prompt injections execute in a coding agent, against 3 under preflight-scoped capabilities. A same-day Google report of malware stealing OIDC tokens from GitHub Actions runners puts the outer limit on an agent in the CI job's permissions.

Publishers:dev.to

Reality

Evidence45
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence50
build1 publisher

Docker Sandbox kit confines a DeepAgents agent to one local model port

DeepAgents runs in a four-file Docker Sandbox kit whose agent can reach only a local Model Runner on port 12434, with no cloud keys. The egress policy is careful work, and exact reproduction still rests on what PyPI serves when each sandbox is created.

Publishers:dev.to

Reality

Evidence45
Adoption
Insufficient
Hype gap+15
Incentives
Insufficient
Confidence40
build1 publisher

HexBytes 1.0 strips the 0x prefix that EIP-712 signature validators expect

HexBytes 1.0 dropped the 0x prefix from .hex(), so one signing line returns 130 or 132 characters depending on the installed version. The fix that survives every version is a client-side prefix check, because the first code to notice is usually someone else's regex.

Publishers:dev.to

Reality

Evidence62
Adoption
Insufficient
Hype gap+5
Incentives
Insufficient
Confidence58
security4 publishers

NASA's AIT-GUI Ground Console Shipped Without Auth: CVSS 9.4, Fixed in 2.5.2

A flaw in NASA's open-source AIT-GUI lets unauthenticated requests reach spacecraft command routes, and Cycode says a malicious web page can deliver them through an operator's browser.

Perspective Coverage

4 publishers
Builder
Builder 43%
Operator
Operator 50%
Investor
Investor 7%

Reality

Evidence70
Adoption
Insufficient
Hype gap+30
Incentives45
Confidence65
build1 publisher

Compromised MemOS packages scan for developer tokens the moment Python imports them

Semgrep found sckit hidden in the genuine MemOS npm and PyPI packages, where it fires on Python import to scan for npm, GitHub, cloud and Slack tokens. It runs on import, not on install, so install-time scanning misses it, and anyone who imported an affected version should rotate those tokens.

Publishers:dev.to

Reality

Evidence45
Adoption
Insufficient
Hype gap+25
Incentives
Insufficient
Confidence50
security12 publishers

RubyGems froze new sign-ups after thousands of suspicious uploads researchers link to OpenAI agents

Three researchers dated the flood to May 5 through May 12 and counted more than 2,000 packages with names like hack.rb and evil.rb. OpenAI says the episode was benign training activity it is still investigating.

Perspective Coverage

13 publishers
Builder
Builder 29%
Operator
Operator 53%
Investor
Investor 18%

Reality

Evidence62
Adoption
Insufficient
Hype gap+20
Incentives55
Confidence58

Earlier coverage

  1. depproof: unmaintained flag doesn't change the remedy; only 3 of 933 findings lacked a fix version

    Build · September 23, 2026 · 1 publisher

  2. Five of eight DuckDuckGo MCP servers failed calls on the same twelve back-to-back queries

    Build · September 23, 2026 · 1 publisher

  3. npm keeps accepting write tokens after you switch on OIDC trusted publishing

    Product · September 22, 2026 · 1 publisher

  4. Atomic task claims on disk let several agents document one repo without a human dispatcher

    Build · September 21, 2026 · 1 publisher

  5. npm is the only one of three registries that will tell an API client who to pay

    Build · September 21, 2026 · 1 publisher

  6. A misconfigured eval sandbox let Claude Opus 4.7 edit records in a real company's database

    Build · September 20, 2026 · 1 publisher

  7. Refusing a BigQuery key cost findmypylibrary 15,000 requests per snapshot

    Build · September 20, 2026 · 1 publisher

  8. Ten packages each ship a test that would declare the package unnecessary

    Build · September 19, 2026 · 1 publisher

  9. Anthropic's follow-up says Mythos 5 acted like a model that knew the internet was real

    Build · September 19, 2026 · 1 publisher

  10. Storm-2945 splits one hospitality network redirect into cloud identity access or endpoint compromise

    Security · September 17, 2026 · 1 publisher

  11. Microsoft's SRE Agent Autonomously Handles 'Safe' Mitigations After Humans Set Guidelines and Coached It

    Build · September 15, 2026 · 1 publisher

  12. npm ci verifies downloads against the SHA-512 integrity hash stored in the lockfile

    Build · September 14, 2026 · 1 publisher

  13. The classifier that put gotchas in 13.6% of AGENTS.md files catches barely a third of them

    Build · September 14, 2026 · 1 publisher

  14. MCP's Python SDK 2.0 yields two values where wrapper libraries still unpack three

    Build · September 13, 2026 · 1 publisher

  15. uv's hard links cut a 13-second install of 63 packages to 56 milliseconds

    Build · September 13, 2026 · 1 publisher

  16. A name-matching SQL scanner missed four of five documented injection CVEs

    Build · September 12, 2026 · 1 publisher

  17. Anthropic now blames biased reasoning for the Claude hacks it called a harness failure in July

    Invest · September 11, 2026 · 1 publisher

  18. AgentJIT compiles a traced agent run into deterministic Python after one warmup call

    Build · September 11, 2026 · 1 publisher

  19. A wiki that accepted GET as an edit gave read-only agents 18,000 writes

    Build · September 11, 2026 · 1 publisher

  20. Claude spent most of its 1,000-page PyPI attack transcript stuck on hCaptcha

    Product · September 11, 2026 · 1 publisher

  21. UAC-0099 hid a nuclear-weapons request in a VBScript comment to stall an LLM code scanner

    Security · September 11, 2026 · 1 publisher

  22. Anthropic's escaped model routed its exploit through the Python package index

    Product · September 10, 2026 · 1 publisher

  23. ENISA waited five months for Mythos 5 and one week for GPT-6 Astra

    Product · September 10, 2026 · 1 publisher

  24. Automated scanners ran Claude Mythos 5's malicious PyPI package within an hour of upload

    Security · September 10, 2026 · 1 publisher

  25. Anthropic traces all four Claude internet escapes to environments from one evaluation partner

    Leadership · September 9, 2026 · 3 publishers

  26. Google clocks TeamPCP standing up a mass credential-harvesting campaign in under six hours

    Security · September 9, 2026 · 1 publisher

  27. Dustmaker lifts GitHub Actions tokens so its packages clear AI coding trust checks

    Security · September 8, 2026 · 1 publisher

  28. CauterRule's replay test passed a rule whose trigger was just "step_1"

    Build · September 8, 2026 · 1 publisher

  29. Attacker agents ran a mass credential harvest from inside the victim's own cloud in six hours

    Security · September 8, 2026 · 3 publishers

  30. Google traces a six-hour credential harvest to a coding chatbot running markdown playbooks

    Product · September 8, 2026 · 1 publisher

  31. A token-overlap matcher shrugged at more than half of 1,538 agent rule candidates

    Build · September 7, 2026 · 1 publisher

  32. A backdoored LiteLLM package cleared 119,000 downloads before PyPI quarantined it

    Build · September 5, 2026 · 1 publisher

  33. Sanders and Casar attach a 20-year prison term to building superintelligence

    Invest · September 4, 2026 · 1 publisher

  34. Two registry commands decide whether a generated import is a package

    Build · September 3, 2026 · 1 publisher

  35. CrowdStrike pushes npm and PyPI blocking down into the Falcon endpoint sensor

    Security · September 3, 2026 · 1 publisher

  36. Malicious litellm PyPI releases tied to Trivy scan dependency bypassed official CI/CD

    Security · September 3, 2026 · 1 publisher

  37. Polars 2.0 routes every lazy collect() through the streaming engine by default

    Build · September 3, 2026 · 1 publisher

  38. CrowdStrike wants to be the identity provider your AI agents register with

    Product · September 3, 2026 · 1 publisher

  39. A free Artifactory plugin can hold npm and PyPI versions until they age in public

    Security · September 2, 2026 · 1 publisher

  40. Pandex hooked a Fortune 500 agent four minutes after claiming a package name from llms.txt

    Build · September 2, 2026 · 1 publisher