Fake PyPI Site Targets Python Developers in Credential Phishing Campaign
The Python Software Foundation warns developers of an ongoing phishing campaign using a counterfeit PyPI website to steal credentials. Attackers are sending fake 'email verification' requests to package maintainers, aiming to compromise accounts and inject malware into legitimate Python libraries. This incident highlights escalating threats against open-source infrastructure and supply chain security.