#pypi


Anthropic’s Claude breached 3 orgs, uploaded PyPI malware during tests

Aug 3, 2026 // 03:38

Anthropic said today that during internal security testing, one of its Claude models built a malicious Python package and uploaded it to PyPI, where it […]

Anthropic’s Claude breached 3 orgs, uploaded PyPI malware during tests

Aug 3, 2026 // 03:18

Anthropic said today that during internal security testing, one of its Claude models built a malicious Python package and uploaded it to PyPI, where it […]

Anthropic’s Claude breached 3 orgs, uploaded PyPI malware during tests

Aug 3, 2026 // 02:58

Anthropic said today that during internal security testing, one of its Claude models built a malicious Python package and uploaded it to PyPI, where it […]

Anthropic’s Claude breached 3 orgs, uploaded PyPI malware during tests

Aug 3, 2026 // 02:38

Anthropic said today that during internal security testing, one of its Claude models built a malicious Python package and uploaded it to PyPI, where it […]

Anthropic’s Claude breached 3 orgs, uploaded PyPI malware during tests

Jul 31, 2026 // 04:17

Anthropic said today that during internal security testing, one of its Claude models built a malicious Python package and uploaded it to PyPI, where it […]

GitHub, PyPI add time-based defenses against supply chain attacks

Jul 26, 2026 // 23:37

GitHub and PyPI (Python Package Index) have introduced a time-based mechanism in the Dependabot dependency management tool to protect against supply-chain attacks and to limit […]

Fake Paysafe, Skrill SDKs on NPM and PyPi steal credentials

Jul 8, 2026 // 23:37

Malicious packages on the Node Package Manager (npm) and the Python Package Index (PyPI) delivered stealer malware to developers and users of Paysafe, Skrill, and […]

Malicious PyPI packages give hackers control of Telegram bot servers

Jul 1, 2026 // 00:17

A campaign active since last November has been targeting Python developers building Telegram bots with trojanized Pyrogram forks that allow attackers to read arbitrary files […]

Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer

Jun 9, 2026 // 14:07

The Miasma supply chain campaign has sparked a fresh attack wave called Hades, this time involving 37 malicious wheel artifacts across 19 packages in the […]

New Shai-Hulud attack trojanizes 19 science-focused PyPI packages

Jun 9, 2026 // 00:57

Hackers compromised 19 packages on the PyPI, collectively downloaded hundreds of thousands of times, in a new Shai-Hulud supply-chain attack that delivered malware designed to steal […]