Close Menu
Pineapples Update –Pineapples Update –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Why Chhaya AI can be the secret to fixing your company’s failed AI projects

    September 3, 2025

    Watch out, whoop: Polar joins the fitness band race with a premium option

    September 3, 2025

    What is Pasaki? Here’s how to set and use them (2025)

    September 3, 2025
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Pineapples Update –Pineapples Update –
    • Home
    • Gaming
    • Gadgets
    • Startups
    • Security
    • How-To
    • AI/ML
    • Apps
    • Web3
    Pineapples Update –Pineapples Update –
    Home»Security»Pyypi now blocks domain resurrection attacks used for kidnapping accounts
    Security

    Pyypi now blocks domain resurrection attacks used for kidnapping accounts

    PineapplesUpdateBy PineapplesUpdateAugust 19, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Pyypi now blocks domain resurrection attacks used for kidnapping accounts
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Pyypi now blocks domain resurrection attacks used for kidnapping accounts

    The Python Package Index (PYPI) has introduced new protection against the domain resurrection attacks that enable kidnapping accounts through the password reset.

    The Pyypi is an official repository for the Open-Sounds Python Package. It is used by companies working with software developers, product version and python library, tools and framework.

    Project Maintenors Publishing Software accounts are associated with email address on PYPI. In the case of some projects, the email address is connected to a domain name.

    If a domain name is terminated, an attacker can register it and use it to install an email server and take control of a project on the PyPI after issuing a password reset request for account.

    The risk from this is a supply-series attack where the kidnapped projects push malicious versions of popular python packages, which will be automatically installed using PIPs in many cases.

    A notable case of such an attack was the agreement of the ‘CTX’ package in May 2022, where a danger actor added code that targeted Amazon AWS Keys and Account Creaients.

    In an attempt to deal with this problem, the Pyypi now checks whether the domains of the email address verified on the platform are finished or are entering the termination stages, and marked those addresses as rejected.

    Technically, the Domainer’s status uses API to determine the life cycle phase (active, grace, redemption period, pending deletion) of the pypi domain, to decide whether action should be taken on a given account.

    Domain lifestyle phase
    Domain lifestyle phase
    Source: PYPI

    Once email addresses enter the position, they cannot be used for password reset or other account recovery functions, thus closing the opportunity window for exploitation, even if an attacker registers domain.

    New remedies Actually entered development in April, when temporary scans were done to evaluate the landscape. Eventually, he was introduced with a daily scan in June 2025. Since then, more than 1,800 email addresses have been rejected under the new system.

    While not foolish or enough against all attack landscapes, new measures significantly reduced the risk of attackers on the pypi accounts through the exploitation of expired domains.

    Pyypi advises users add a backup email to their account to a non-custom domain to avoid disruption, and enable two-factor authentication on their PYPI account for strong security against kidnapping.


    Picus Blue Report 2025

    The passwords broke in 46% of the atmosphere, almost doubled by 25% last year.

    Picus Blue Report 2025 Now get a wider look at more conclusions on prevention, detection and data exfIs.

    accounts attacks blocks domain kidnapping Pyypi Resurrection
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleBlockchain native protocols become creative in Crypto Treasury Arms Race
    Next Article Sony’s newest headphones are for those who love the game – and I can pay attention to it
    PineapplesUpdate
    • Website

    Related Posts

    Security

    Why Chhaya AI can be the secret to fixing your company’s failed AI projects

    September 3, 2025
    Security

    What is Pasaki? Here’s how to set and use them (2025)

    September 3, 2025
    Security

    Jaguar Land Rover says Cyberlack ‘severely interrupted’ production

    September 3, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Microsoft’s new text editor is a VIM and Nano option

    May 19, 2025797 Views

    The best luxury car for buyers for the first time in 2025

    May 19, 2025724 Views

    Massives Datenleck in Cloud-Spichenn | CSO online

    May 19, 2025650 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    10,000 steps or Japanese walk? We ask experts if you should walk ahead or fast

    June 16, 20250 Views

    FIFA Club World Cup Soccer: Stream Palmirus vs. Porto lives from anywhere

    June 16, 20250 Views

    What do chatbott is careful about punctuation? I tested it with chat, Gemini and Cloud

    June 16, 20250 Views
    Our Picks

    Why Chhaya AI can be the secret to fixing your company’s failed AI projects

    September 3, 2025

    Watch out, whoop: Polar joins the fitness band race with a premium option

    September 3, 2025

    What is Pasaki? Here’s how to set and use them (2025)

    September 3, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms And Conditions
    • Disclaimer
    © 2025 PineapplesUpdate. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.