MIT TRACE

MIT CTL Logo
Back to Main Dashboard

PyPI malware campaign forced a 10-hour suspension of new projects and registrations

On March 28, the Python Package Index suspended new project creation and new user registration to mitigate an ongoing campaign that uploaded malicious typosquatting packages; the restrictions were lifted about 10 hours later. PyPI is developed and maintained by the Python Software Foundation, making the foundation the identifiable operator whose software-distribution service was materially restricted during the incident.

65

Estimated severity

65 / 100

92

Source reliability

92 / 100

Approximate Date

28/03/2024

Targeted Company

PYTHON SOFTWARE FOUNDATION

Targeted Company Supply Chain Impact

  1. Distribution & Fulfillment

  2. Procurement & Sourcing

  3. Production & Manufacturing

  4. Sales (Retail & Ecommerce)

  5. Warehousing

  6. Service Delivery

  7. Unrecognized Impact

Supply Chain Relations

No information

Geographic Impact

Country Targeted Company

United States

USA

Other Affected Countries

No other affected countries reported

Target country

United States

Affected countries

No information

Impacted regions

No information

Operational Impact

Duration

0.42 days

Financial impact (USD M)

No information

Impact types

Service unavailabilityOperational disruption

Affected sectors

Technology & IT Services

Affected departments

Information Technology

Attack Profile

Attack types

Malware

Attributed threat actors

No information

Sources

Please rotate your phone

MIT TRACE is optimized for landscape orientation on mobile.