#pypi search results

I was annoyed of having to write README files for my projects. So I went ahead and created a CLI tool to auto-generate README files for any project regardless of programming language! 📜✨ It creates a comprehensive README based on your project. Check it out on #PyPI and #npm

plastic96_'s tweet image. I was annoyed of having to write README files for my projects.

So I went ahead and created a CLI tool to auto-generate README files for any project regardless of programming language! 📜✨

It creates a comprehensive README based on your project. Check it out on #PyPI and #npm
plastic96_'s tweet image. I was annoyed of having to write README files for my projects.

So I went ahead and created a CLI tool to auto-generate README files for any project regardless of programming language! 📜✨

It creates a comprehensive README based on your project. Check it out on #PyPI and #npm

🎉 Just published bip329 v1.0.0 to PyPI! pip install bip329==1.0.0 #Python #PyPI #OpenSource #bip329

xavierfiechter's tweet image. 🎉 Just published bip329 v1.0.0 to PyPI!  

pip install bip329==1.0.0 

#Python #PyPI #OpenSource #bip329

How do you optimize package delivery for 950,000+ Python developers? Check out how we're using Individual Provider Anycast to power platforms like @PyPI, where small improvements × billions of requests = massive impact! fastly.com/blog/powering-… #fastforward #pypi

fastly's tweet image. How do you optimize package delivery for 950,000+ Python developers? Check out how we're using Individual Provider Anycast to power platforms like @PyPI, where small improvements × billions of requests = massive impact!
fastly.com/blog/powering-…
#fastforward #pypi

PyPI serves billions of requests daily- but sustaining it isn’t free. The PSF joined the OpenSSF & others in calling for organizations to invest in sustainable open infrastructure. Learn what this means for #PyPI, the PSF, & how our community can pitch in: pyfound.blogspot.com/2025/10/open-i…


🚨 We discovered two malicious Python packages in #PyPI repository that remained undetected for over a year. These packages mimicked tools for working with popular AI language models (#ChatGPT and #Claude), silently exfiltrating data and compromising developer environments.…

bzvr_'s tweet image. 🚨  We discovered two malicious Python packages in #PyPI repository that remained undetected for over a year. These packages mimicked tools for working with popular AI language models (#ChatGPT and #Claude), silently exfiltrating data and compromising developer environments.…

It's been a busy day for us! ⚠️🧵 RL's automated detection system flagged a new malicious #PyPI package: secure.software/pypi/packages/… While name would suggest this is a ChatGPT related project, it actually contains a #malware loader.

ReversingLabs's tweet image. It's been a busy day for us! ⚠️🧵 RL's automated detection system flagged a new malicious #PyPI package: secure.software/pypi/packages/…

While name would suggest this is a ChatGPT related project, it actually contains a #malware loader.

#OceanLotus #APT32 #PyPi uuid32_utils-1.x.x-py3-none-win32.whl cf3f59e2c4c8767697ea46475171697c 91a476fea45abc8b208e0a9e3293f774 a7a0add66b205967562c1fa9643b8421 22538214a3c917ff3b13a9e2035ca521 02f4701559fc40067e69bb426776a54f 5598baa59c716590d8841c6312d8349e Backward.dll…

SethKingHi's tweet image. #OceanLotus #APT32 #PyPi

uuid32_utils-1.x.x-py3-none-win32.whl
cf3f59e2c4c8767697ea46475171697c
91a476fea45abc8b208e0a9e3293f774
a7a0add66b205967562c1fa9643b8421
22538214a3c917ff3b13a9e2035ca521
02f4701559fc40067e69bb426776a54f
5598baa59c716590d8841c6312d8349e

Backward.dll…
SethKingHi's tweet image. #OceanLotus #APT32 #PyPi

uuid32_utils-1.x.x-py3-none-win32.whl
cf3f59e2c4c8767697ea46475171697c
91a476fea45abc8b208e0a9e3293f774
a7a0add66b205967562c1fa9643b8421
22538214a3c917ff3b13a9e2035ca521
02f4701559fc40067e69bb426776a54f
5598baa59c716590d8841c6312d8349e

Backward.dll…
SethKingHi's tweet image. #OceanLotus #APT32 #PyPi

uuid32_utils-1.x.x-py3-none-win32.whl
cf3f59e2c4c8767697ea46475171697c
91a476fea45abc8b208e0a9e3293f774
a7a0add66b205967562c1fa9643b8421
22538214a3c917ff3b13a9e2035ca521
02f4701559fc40067e69bb426776a54f
5598baa59c716590d8841c6312d8349e

Backward.dll…

⚠️🧵 RL threat researchers detected an impersonation attempt targeting a popular #PyPI cloudscraper package with more than 50M downloads. It has the suffix "safe" added, but it is all but safe: secure.software/pypi/packages/…

ReversingLabs's tweet image. ⚠️🧵 RL threat researchers detected an impersonation attempt targeting a popular #PyPI cloudscraper package with more than 50M downloads. It has the suffix "safe" added, but it is all but safe: secure.software/pypi/packages/…

🚨Over 22k packages are vulnerable (or over 120k by looser measurement) to a new #SoftwareSupplyChain attack vector: Hijacking abandoned #PyPI packages. Potentially critical for orgs relying on abandoned packages, learn more about our team's discovery: jfrog.co/4gpsbUH

JFrogSecurity's tweet image. 🚨Over 22k packages are vulnerable (or over 120k by looser measurement) to a new #SoftwareSupplyChain attack vector: Hijacking abandoned #PyPI packages.

Potentially critical for orgs relying on abandoned packages, learn more about our team's discovery: jfrog.co/4gpsbUH

🔖 Zenn過去記事投稿 自分だけのライブラリを作ってみよう! 【Pythonで自分だけのクソライブラリを作る方法】 ✅ PyPIへの公開手順を解説 ✅ パッケージ構成のベストプラクティス ✅ 実用的なライブラリ開発のコツ #Python #ライブラリ開発 #PyPI #OSS zenn.dev/karaage0703/ar…


🚨Over 22k packages are vulnerable (or over 120k by looser measurement) to a new #SoftwareSupplyChain attack vector: Hijacking abandoned #PyPI packages. Potentially critical for orgs relying on abandoned packages, learn more about our team's discovery: jfrog.co/4gpsbUH

jfrog's tweet image. 🚨Over 22k packages are vulnerable (or over 120k by looser measurement) to a new #SoftwareSupplyChain attack vector: Hijacking abandoned #PyPI packages.

Potentially critical for orgs relying on abandoned packages, learn more about our team's discovery: jfrog.co/4gpsbUH

#DeepSeek’s popularity exploited to push malicious packages via #PyPI securitytc.com/THlZ6L

evanderburg's tweet image. #DeepSeek’s popularity exploited to push malicious packages via #PyPI securitytc.com/THlZ6L

"This attack technique involves hijacking PyPI software packages by manipulating the option to re-register them once they're removed from #PyPI's index by the original owner," JFrog security researchers Andrey Polkovnychenko & Brian Moussalli Learn more: jfrog.co/4cSgBOK

jfrog's tweet image. "This attack technique involves hijacking PyPI software packages by manipulating the option to re-register them once they're removed from #PyPI's index by the original owner," JFrog security researchers Andrey Polkovnychenko & Brian Moussalli

Learn more: jfrog.co/4cSgBOK

This is done by Termspark 🔥 Text blink, italic text and more styles support on next release (1.7.0) Wait for it! #python #pypi #opensource


🎉 ActiveState is pleased to announce our inclusion as a Trusted Publisher to PyPI, enabling Python authors to securely publish Python packages directly via ActiveState’s Platform. Become a trusted author today: ow.ly/Z34i50RikiO #ActiveState #TrustedPublisher #PyPI


A new supply chain attack on PyPI is delivering SilentSync, a Python RAT. The malware steals credentials and files from developers' systems. #PyPI #SupplyChainAttack #Python #Malware #Cybersecurity securityonline.info/pypi-under-att…


Dustin Ingram (Google Open Source Security Team member, PSF director, Python Package Index maintainer) is giving the talk "Software Security and Slippery Slopes" at PyCon US 2023 🇺🇲🐍 #PyCon #PyConUS #PyPi #Python #PythonSpeakingTour CC @pycon @di_codes

pauloxnet's tweet image. Dustin Ingram (Google Open Source Security Team member,  PSF director, Python Package Index maintainer) is giving the talk "Software Security and Slippery Slopes" at PyCon US 2023 🇺🇲🐍

#PyCon #PyConUS #PyPi #Python #PythonSpeakingTour 

CC @pycon @di_codes
pauloxnet's tweet image. Dustin Ingram (Google Open Source Security Team member,  PSF director, Python Package Index maintainer) is giving the talk "Software Security and Slippery Slopes" at PyCon US 2023 🇺🇲🐍

#PyCon #PyConUS #PyPi #Python #PythonSpeakingTour 

CC @pycon @di_codes
pauloxnet's tweet image. Dustin Ingram (Google Open Source Security Team member,  PSF director, Python Package Index maintainer) is giving the talk "Software Security and Slippery Slopes" at PyCon US 2023 🇺🇲🐍

#PyCon #PyConUS #PyPi #Python #PythonSpeakingTour 

CC @pycon @di_codes
pauloxnet's tweet image. Dustin Ingram (Google Open Source Security Team member,  PSF director, Python Package Index maintainer) is giving the talk "Software Security and Slippery Slopes" at PyCon US 2023 🇺🇲🐍

#PyCon #PyConUS #PyPi #Python #PythonSpeakingTour 

CC @pycon @di_codes

From the #pydantic #Python library page on #PyPi: '...but the error wasn't raised concistently.' If you have spelling errors in your code as you do in your documentation, then things may not work correctly. Just saying. <rolls eyes>


Imagine how good it would be if pages on #PyPi stated which versions things were built against, so you would know immediately instead of mangling your installations multiple times over while finding out the hard way... #Python #AI


building, and much more! Try it now with a simple pip install cognautic-cli and leverage AI directly in your terminal. #CognauticCLI #PyPI #OpenSource #AI #DeveloperTools #PythonCLI #CodingAssistant #AIForDevelopers


Even still, we’re raising the flag early: the PSF has only ~6 months of runway and needs your support to sustain essential #Python & #PyPI infrastructure, #PyConUS, and, hopefully, to reopen our Grants Program.


Exciting news for developers! 🚀 Just added jupyterlab-nbpath to PyPI!💻 This tool simplifies notebook navigation in JupyterLab. Check it out on PyPI: pypi.org/project/jupyte… #DeveloperTools #Python #PyPI


PyPI serves billions of requests daily- but sustaining it isn’t free. The PSF joined the OpenSSF & others in calling for organizations to invest in sustainable open infrastructure. Learn what this means for #PyPI, the PSF, & how our community can pitch in: pyfound.blogspot.com/2025/10/open-i…


🔖 Zenn過去記事投稿 自分だけのライブラリを作ってみよう! 【Pythonで自分だけのクソライブラリを作る方法】 ✅ PyPIへの公開手順を解説 ✅ パッケージ構成のベストプラクティス ✅ 実用的なライブラリ開発のコツ #Python #ライブラリ開発 #PyPI #OSS zenn.dev/karaage0703/ar…


#npm, #PyPI, and #RubyGems Packages Found Sending #Developer Data to #Discord Channels ift.tt/STKr63H

omvapt's tweet image. #npm, #PyPI, and #RubyGems Packages Found Sending #Developer Data to #Discord Channels 
ift.tt/STKr63H

🎉 Launched my first package on #PyPI C-based HTTP client for #Python that mimics browser #fingerprint to bypass SSL blocks. ✅ Python 3.8-3.14 ✅ Linux, Windows, macOS ✅ 270 test cases ✅ requests compatible PyPI: pypi.org/project/httpmo… Github: github.com/arman-bd/httpm…

armanfixing's tweet image. 🎉 Launched my first package on #PyPI

C-based HTTP client for #Python that mimics browser #fingerprint to bypass SSL blocks.

✅ Python 3.8-3.14 
✅ Linux, Windows, macOS
✅ 270 test cases
✅ requests compatible

PyPI: pypi.org/project/httpmo…
Github: github.com/arman-bd/httpm…

Don't be surprised if you have crashing issues with xformers 0.0.33.dev1085. Stick to the dev1083 release for now, would be my recommendation, unless you know better. #xformers #Python #pypi #PythonLibraries #Attention #GenerativeAI #AIcoding


🚨 A malicious #PyPI package, #soopsocks, has already infected 2,600+ systems. Get the breakdown on how it works, the red flags to watch for, and steps to prevent similar #SoftwareSupplyChain threats, research powered by JFrog. 🔗 Learn more: bit.ly/48dS1cx


The malicious PyPI package SoopSocks masqueraded as a SOCKS5 proxy but secretly installed a Go-based backdoor with SYSTEM privileges, leaking system data to a Discord webhook. #SoopSocks #PyPI #SupplyChain #Backdoor #Cybersecurity securityonline.info/backdoor-disgu…


🚨 Developers, a malicious PyPI package 'soopsocks' infected over 2,600 systems before being taken down! Check your dependencies and stay vigilant against supply chain attacks. #PyPI #Cybersecurity thehackernews.com/2025/10/alert-…


The #HuggingFace hosted models are added to the 🦉🫥 PDF Anonymizer (see the #PyPi pdf-anonymizer-cli). I'm adding more LLM options. #anonymizer


🚨 Alert: Malicious PyPI package soopsocks infected 2,653 systems before takedown. Python developers, update & audit dependencies now! ⚠️ #CyberSecurity #PyPI #Malware #SupplyChainAttack

SecurEpitome's tweet image. 🚨 Alert: Malicious PyPI package soopsocks infected 2,653 systems before takedown.
Python developers, update &amp;amp; audit dependencies now! ⚠️
#CyberSecurity #PyPI #Malware #SupplyChainAttack

💣 Among others, @sekoia_io discovered yesterday 55 #PyPI malicious packages pushed by the same Threat actor. It's not the first time that we are seeing this actor pushing this kind of malicious packages. PyPI contacted and packages removed 👌 Related packages and IoCs below ↘️

sekoia_io's tweet image. 💣 Among others, @sekoia_io discovered yesterday 55 #PyPI malicious packages pushed by the same Threat actor.

It&apos;s not the first time that we are seeing this actor pushing this kind of malicious packages. PyPI contacted and packages removed 👌

Related packages and IoCs below ↘️

#PyPI 上に悪意のあるパッケージが6つ見つかりました。背後にいる攻撃者は #W4SP の攻撃を模倣し、ユーザークレデンシャル、暗号ウォレット データなどを窃取していました。オープンソース エコシステムに台頭しつつある脅威の動向を解説します。 bit.ly/44CjShk

unit42_jp's tweet image. #PyPI 上に悪意のあるパッケージが6つ見つかりました。背後にいる攻撃者は #W4SP の攻撃を模倣し、ユーザークレデンシャル、暗号ウォレット データなどを窃取していました。オープンソース エコシステムに台頭しつつある脅威の動向を解説します。 bit.ly/44CjShk

🎉 Just published bip329 v1.0.0 to PyPI! pip install bip329==1.0.0 #Python #PyPI #OpenSource #bip329

xavierfiechter's tweet image. 🎉 Just published bip329 v1.0.0 to PyPI!  

pip install bip329==1.0.0 

#Python #PyPI #OpenSource #bip329

Looking back at 2023 @mikefiedler discovered some impressive metrics that we want to share! @fastly #PyPI #pytho

pypi's tweet image. Looking back at 2023 @mikefiedler discovered some impressive metrics that we want to share! @fastly #PyPI #pytho

🔍Researchers have discovered a concerning surge in deceptive #npm and #PyPI packages distributed as part of a malicious campaign, aimed at extracting #Kubernetes configurations and #SSH keys. Read more👇 socradar.io/new-campaign-d… #cybersecurity #devops #supplychain #datatheft

socradar's tweet image. 🔍Researchers have discovered a concerning surge in deceptive #npm and #PyPI packages distributed as part of a malicious campaign, aimed at extracting #Kubernetes configurations and #SSH keys.

Read more👇
socradar.io/new-campaign-d…  

#cybersecurity #devops #supplychain #datatheft

#PyPI A good blog post with analysis of #malicious #Python packages in PyPI by the @eset research team: #SoftwareSupplyChainSecurity 👇 welivesecurity.com/en/eset-resear…

securestep9's tweet image. #PyPI A good blog post with analysis of #malicious #Python packages in PyPI by the @eset research team:
#SoftwareSupplyChainSecurity

👇
welivesecurity.com/en/eset-resear…

#Python: #PyPI temporarily shuts down new project creation and new user registration to mitigate an ongoing #malware upload campaign:

securestep9's tweet image. #Python: #PyPI temporarily shuts down new project creation and new user registration to mitigate an ongoing #malware upload campaign:

Pypi is having severe problems with malware and malicious projects 😞🤬 be careful #python #pypi

ggdaniel's tweet image. Pypi is having severe problems with malware and malicious projects 😞🤬 be careful #python #pypi

⚠️🧵 RL researchers detected a new malicious campaign targeting #PyPI users. Several packages are pretending to be "time" related utilities, but are actually used to steal sensitive data like cloud tokens.

ReversingLabs's tweet image. ⚠️🧵 RL researchers detected a new malicious campaign targeting #PyPI users. Several packages are pretending to be &quot;time&quot; related utilities, but are actually used to steal sensitive data like cloud tokens.

Malicious packages disguised as legitimate software pose a threat to #cloud systems. Our new research spotlights a technical analysis of six packages meant for #CredentialStealing, personal data stealing and more found in the Python Package Index (#PyPI). bit.ly/44Bdgjl

Unit42_Intel's tweet image. Malicious packages disguised as legitimate software pose a threat to #cloud systems. Our new research spotlights a technical analysis of six packages meant for #CredentialStealing, personal data stealing and more found in the Python Package Index (#PyPI). bit.ly/44Bdgjl

What are some suspicious attributes of code packages? These can include no associated #GitHub repo, limited downloads or a malicious code pattern. We break down the discovery of six malicious packages found on the popular #PyPI repository. bit.ly/44Bdgjl

Unit42_Intel's tweet image. What are some suspicious attributes of code packages? These can include no associated #GitHub repo, limited downloads or a malicious code pattern. We break down the discovery of six malicious packages found on the popular #PyPI repository. bit.ly/44Bdgjl

🚨 We discovered two malicious Python packages in #PyPI repository that remained undetected for over a year. These packages mimicked tools for working with popular AI language models (#ChatGPT and #Claude), silently exfiltrating data and compromising developer environments.…

bzvr_'s tweet image. 🚨  We discovered two malicious Python packages in #PyPI repository that remained undetected for over a year. These packages mimicked tools for working with popular AI language models (#ChatGPT and #Claude), silently exfiltrating data and compromising developer environments.…

Is it possible to encounter #malware on #PyPI? Learn how CloudGuard Spectralops.io - A Check Point Solution detected a malicious package on the leading #Python repository: bit.ly/3Zgo5V7

CheckPointSW's tweet image. Is it possible to encounter #malware on #PyPI? Learn how CloudGuard Spectralops.io - A Check Point Solution detected a malicious package on the leading #Python repository: bit.ly/3Zgo5V7

🔍Recently, researchers identified three malicious #Python packages on the #PyPI, tied to #VMConnect campaign, and attributed it to the #LazarusGroup. 🔻Explore our #APT profile to gain insights into #Lazarus and learn about the campaign: 🔗socradar.io/apt-profile-wh…

socradar's tweet image. 🔍Recently, researchers identified three malicious #Python packages on the #PyPI, tied to #VMConnect campaign, and attributed it to the #LazarusGroup. 

🔻Explore our #APT profile to gain insights into #Lazarus and learn about the campaign: 

🔗socradar.io/apt-profile-wh…

Find out how a malicious code sneaked into one of the packages, secretly collecting sensitive data from Windows users. Explore more at bit.ly/44689rF #PyPI #PythonPackages #SecurityThreats #StayInformed #cyberthreats

k7computing's tweet image. Find out how a malicious code sneaked into one of the packages, secretly collecting sensitive data from Windows users. Explore more at bit.ly/44689rF

#PyPI #PythonPackages #SecurityThreats #StayInformed #cyberthreats

I was annoyed of having to write README files for my projects. So I went ahead and created a CLI tool to auto-generate README files for any project regardless of programming language! 📜✨ It creates a comprehensive README based on your project. Check it out on #PyPI and #npm

plastic96_'s tweet image. I was annoyed of having to write README files for my projects.

So I went ahead and created a CLI tool to auto-generate README files for any project regardless of programming language! 📜✨

It creates a comprehensive README based on your project. Check it out on #PyPI and #npm
plastic96_'s tweet image. I was annoyed of having to write README files for my projects.

So I went ahead and created a CLI tool to auto-generate README files for any project regardless of programming language! 📜✨

It creates a comprehensive README based on your project. Check it out on #PyPI and #npm

Loading...

Something went wrong.


Something went wrong.


United States Trends