# PyPI.org Phishing attack

**URL:** <https://discuss.python.org/t/pypi-org-phishing-attack/100267>\
**Category:** Packaging\
**Tags:** PyPI\
**Created:** [July 26, 2025, 10:37pm UTC](https://discuss.python.org/t/pypi-org-phishing-attack/100267 "2025-07-26T22:37:15Z")\
**Posts on this page:** 16\
**Page:** 1

<div class="post-metadata">

**Author:** ![stoneleaf](https://sea2.discourse-cdn.com/flex002/user_avatar/discuss.python.org/stoneleaf/32/88_2.png) [@stoneleaf](https://discuss.python.org/u/stoneleaf)\
**Post date:** [July 26, 2025, 10:37pm UTC](https://discuss.python.org/t/pypi-org-phishing-attack/100267/1 "2025-07-26T22:37:15Z")

</div>

I just received this email (link deliberately broken):

> As part of our ongoing account maintenance and security procedures, we’re asking users to verify their email addresses.
> 
> Please follow [this link](http s://pypj.org/account/login?user=ethan&token=xxx) to verify your email address.
> 
> This link will expire in 72 hours.
> 
> If you fail to confirm your email we may remove that email from your account to ensure your security.

Is pypj (that’s a J, not an I) one of ours?

---

<div class="post-metadata">

**Author:** ![MegaIng](https://sea2.discourse-cdn.com/flex002/user_avatar/discuss.python.org/megaing/32/16162_2.png) [@MegaIng](https://discuss.python.org/u/MegaIng)\
**Post date:** [July 26, 2025, 10:50pm UTC](https://discuss.python.org/t/pypi-org-phishing-attack/100267/2 "2025-07-26T22:50:19Z")

</div>

Definitely a fake website. If you check in the footer, some links like `donate.pypj.org` are broken because they aren’t quite spoofing everything and are instead trying to do a more simple `pypi` → `pypj` text replacement which doesn’t always work.

Probably worth reporting to google who are currently providing the certificate for this domain.

---

<div class="post-metadata">

**Author:** ![loic-simon](https://sea2.discourse-cdn.com/flex002/user_avatar/discuss.python.org/loic-simon/32/37461_2.png) [@loic-simon](https://discuss.python.org/u/loic-simon)\
**Post date:** [July 26, 2025, 10:54pm UTC](https://discuss.python.org/t/pypi-org-phishing-attack/100267/3 "2025-07-26T22:54:05Z")

</div>

> [@MegaIng](#):
>
> Probably worth reporting to google who are currently providing the certificate for this domain.

That can be done here: [https://safebrowsing.google.com/safebrowsing/report\_phish/](https://safebrowsing.google.com/safebrowsing/report_phish/) (according to [the FAQ](https://pki.goog/faq/#faq-phishing))

---

<div class="post-metadata">

**Author:** ![stoneleaf](https://sea2.discourse-cdn.com/flex002/user_avatar/discuss.python.org/stoneleaf/32/88_2.png) [@stoneleaf](https://discuss.python.org/u/stoneleaf)\
**Post date:** [July 26, 2025, 11:31pm UTC](https://discuss.python.org/t/pypi-org-phishing-attack/100267/4 "2025-07-26T23:31:57Z")

</div>

Thanks, both! Site reported.

---

<div class="post-metadata">

**Author:** ![AA-Turner](https://sea2.discourse-cdn.com/flex002/user_avatar/discuss.python.org/aa-turner/32/4979_2.png) [@AA-Turner](https://discuss.python.org/u/AA-Turner)\
**Post date:** [July 27, 2025, 1:00am UTC](https://discuss.python.org/t/pypi-org-phishing-attack/100267/5 "2025-07-27T01:00:39Z")

</div>

The site is also using Cloudflare name servers, and is registered with NameSilo LLC, so the abuse reporting for both firms can be used: [https://abuse.cloudflare.com](https://abuse.cloudflare.com) / [abuse@namesilo.com](mailto:abuse@namesilo.com). I’ve also sent an email to the PSF trademarks committee for obvious trademark infringement.

See [https://rdap.namesilo.com/domain/pypj.org](https://rdap.namesilo.com/domain/pypj.org) & [ICANN Lookup](https://lookup.icann.org/en/lookup).

A

---

<div class="post-metadata">

**Author:** ![EWDurbin](https://sea2.discourse-cdn.com/flex002/user_avatar/discuss.python.org/ewdurbin/32/3103_2.png) [@EWDurbin](https://discuss.python.org/u/EWDurbin)\
**Post date:** [July 27, 2025, 11:01am UTC](https://discuss.python.org/t/pypi-org-phishing-attack/100267/6 "2025-07-27T11:01:18Z")

</div>

I have reports on the behalf of the PSF in at this time, and I’m aware that the trademark working group is also working from their angle. Thanks everyone.

---

<div class="post-metadata">

**Author:** ![malemburg](https://sea2.discourse-cdn.com/flex002/user_avatar/discuss.python.org/malemburg/32/50_2.png) [@malemburg](https://discuss.python.org/u/malemburg)\
**Post date:** [July 27, 2025, 11:31am UTC](https://discuss.python.org/t/pypi-org-phishing-attack/100267/7 "2025-07-27T11:31:59Z")

</div>

Thanks for reporting this, @stoneleaf

I updated the title since this is a real attack. Perhaps we should send out a warning to users on one of the announcement and security channels.

---

<div class="post-metadata">

**Author:** ![christippett](https://sea2.discourse-cdn.com/flex002/user_avatar/discuss.python.org/christippett/32/29470_2.png) [@christippett](https://discuss.python.org/u/christippett)\
**Post date:** [July 27, 2025, 2:28pm UTC](https://discuss.python.org/t/pypi-org-phishing-attack/100267/8 "2025-07-27T14:28:47Z")

</div>

This discussion is the top Google result when searching for “[pypj.org](http://pypj.org)”… I also received the same email verification request and was suspicious of the domain. I have a real [pypi.org](http://pypi.org) account associated with the same email the (fake) verification request was sent to.

I’m a nobody, so if I got this email there’s likely a lot more who also received the same phishing email. One of my projects was marked once as critical, so that could be the criteria they’re using for who to target.

Happy to provide email headers and any other info if requested.

---

<div class="post-metadata">

**Author:** ![webknjaz](https://sea2.discourse-cdn.com/flex002/user_avatar/discuss.python.org/webknjaz/32/2699_2.png) [@webknjaz](https://discuss.python.org/u/webknjaz)\
**Post date:** [July 28, 2025, 9:16am UTC](https://discuss.python.org/t/pypi-org-phishing-attack/100267/9 "2025-07-28T09:16:04Z")

</div>

I got one too and just wanted to document that the email isn’t assigned to an actual PyPI account but is included in the core packaging meta and so it’s exposed publicly.

It’s a `team@` address with forwarding to actual humans. And the scam “verification” URL just extracted the part before `@` to inject into the GET param.

 ![1000016634](https://us1.discourse-cdn.com/flex002/uploads/python1/original/3X/e/e/ee6277ef0936e529e1729a14e6d7418c536611c1.jpeg)

---

<div class="post-metadata">

**Author:** ![miketheman](https://sea2.discourse-cdn.com/flex002/user_avatar/discuss.python.org/miketheman/32/6483_2.png) [@miketheman](https://discuss.python.org/u/miketheman)\
**Post date:** [July 28, 2025, 3:24pm UTC](https://discuss.python.org/t/pypi-org-phishing-attack/100267/10 "2025-07-28T15:24:44Z")

</div>

Hi gang,

Thanks for your diligence!

Some notices have gone up on social media, mailing lists, and PyPI blog:

> **[PyPI Users Email Phishing Attack - The Python Package Index Blog](https://blog.pypi.org/posts/2025-07-28-pypi-phishing-attack/)**
>
> PyPI Users are receiving emails detailing them to log in to a fake PyPI site.

Other efforts are underway to evaluate the impact and look at other prevention techniques.

---

<div class="post-metadata">

**Author:** ![EWDurbin](https://sea2.discourse-cdn.com/flex002/user_avatar/discuss.python.org/ewdurbin/32/3103_2.png) [@EWDurbin](https://discuss.python.org/u/EWDurbin)\
**Post date:** [July 28, 2025, 4:04pm UTC](https://discuss.python.org/t/pypi-org-phishing-attack/100267/11 "2025-07-28T16:04:53Z")

</div>

We have implemented a client side protection that should block the trivial proxy attacks like these, and are working with our CDN provider, Fastly, to determine if any of their security products would further protect us from these attacks.

 ![screenshot_2025-07-28_at_11.46.45___am_720](https://us1.discourse-cdn.com/flex002/uploads/python1/original/3X/7/e/7e128063ec779c4fcc348a0406aa9aa5103082e9.png)

---

<div class="post-metadata">

**Author:** ![EWDurbin](https://sea2.discourse-cdn.com/flex002/user_avatar/discuss.python.org/ewdurbin/32/3103_2.png) [@EWDurbin](https://discuss.python.org/u/EWDurbin)\
**Post date:** [July 28, 2025, 4:21pm UTC](https://discuss.python.org/t/pypi-org-phishing-attack/100267/12 "2025-07-28T16:21:10Z")

</div>

Cloudflare has also now flagged to the domain.

 ![Screenshot 2025-07-28 at 12.20.29 PM](https://us1.discourse-cdn.com/flex002/uploads/python1/original/3X/9/0/90b63e72e3dc4d55634a3b46950c91090aad1fad.png)

---

<div class="post-metadata">

**Author:** ![EWDurbin](https://sea2.discourse-cdn.com/flex002/user_avatar/discuss.python.org/ewdurbin/32/3103_2.png) [@EWDurbin](https://discuss.python.org/u/EWDurbin)\
**Post date:** [July 28, 2025, 4:51pm UTC](https://discuss.python.org/t/pypi-org-phishing-attack/100267/13 "2025-07-28T16:51:40Z")

</div>

The domain registrar has also placed this domain on a hold.

---

<div class="post-metadata">

**Author:** ![miketheman](https://sea2.discourse-cdn.com/flex002/user_avatar/discuss.python.org/miketheman/32/6483_2.png) [@miketheman](https://discuss.python.org/u/miketheman)\
**Post date:** [July 31, 2025, 5:10pm UTC](https://discuss.python.org/t/pypi-org-phishing-attack/100267/14 "2025-07-31T17:10:15Z")

</div>

The incident is over, and here’s a deeper dive.

> **[PyPI Phishing Attack: Incident Report - The Python Package Index Blog](https://blog.pypi.org/posts/2025-07-31-incident-report-phishing-attack/)**
>
> Follow-up on the recent phishing attack targeting PyPI users.

---

<div class="post-metadata">

**Author:** ![webknjaz](https://sea2.discourse-cdn.com/flex002/user_avatar/discuss.python.org/webknjaz/32/2699_2.png) [@webknjaz](https://discuss.python.org/u/webknjaz)\
**Post date:** [September 26, 2025, 10:47pm UTC](https://discuss.python.org/t/pypi-org-phishing-attack/100267/15 "2025-09-26T22:47:27Z")

</div>

Looks like there’s a new phishing domain with similar attack mechanics — I’ve found this 3-days old thing in my spam folder:

 ![1000017423](https://us1.discourse-cdn.com/flex002/uploads/python1/original/3X/6/2/620cf6dc95f49667b3153906989b44c62c5cc0aa.jpeg)

 ![1000017425](https://us1.discourse-cdn.com/flex002/uploads/python1/original/3X/4/a/4ab041f4a84b8ac0e73a4f08be6c33ebf05496f8.jpeg)

 ![1000017424](https://us1.discourse-cdn.com/flex002/uploads/python1/original/3X/1/3/13d94a73a88841b118aa940e61e85a7aa9419edd.jpeg)

cc @miketheman @sethmlarson

---

<div class="post-metadata">

**Author:** ![sethmlarson](https://sea2.discourse-cdn.com/flex002/user_avatar/discuss.python.org/sethmlarson/32/1644_2.png) [@sethmlarson](https://discuss.python.org/u/sethmlarson)\
**Post date:** [September 26, 2025, 11:06pm UTC](https://discuss.python.org/t/pypi-org-phishing-attack/100267/16 "2025-09-26T23:06:28Z")

</div>

Thanks for reporting, we responded additionally to the new domain: [Phishing attacks with new domains likely to continue - The Python Package Index Blog](https://blog.pypi.org/posts/2025-09-23-plenty-of-phish-in-the-sea/)

It’s likely this will continue with different domains, so we might start re-using blog posts with slight updates to avoid needing to constantly emit the same recommendations with only the domain name changed.
