Last Update: 09/22/2026 at 11:34 PM EST
PyPI Supply-Chain Credential Theft
Coverage from BleepingComputer, OX Security, and others

Recent reports describe malicious PyPI package uploads that run on import, add persistence, and steal cloud credentials, SSH keys, tokens, and other secrets from Python environments.
Looking Back
99 Day Timeline
Mar 24
Apr 9
Apr 25
May 13
May 29
Jun 14
Jun 30
All Articles4 articles
Additional
6/30/2026 • Cybersecurity Tech (Privacy-Relevant) • General
3/27/2026 • Cybersecurity (Privacy-Relevant) • General
4/22/2026 • Cybersecurity (Privacy-Relevant) • General
3/24/2026 • Cybersecurity (Privacy-Relevant) • General
