Python Packaging Council Holds Its Inaugural Election as 17 Candidates Vie for Five Seats
The Python Software Foundation announced 17 candidates for the first Python Packaging Council election on August 13, with voting scheduled for September 1-15.
Signal
8 articles covering "pypi"
The Python Software Foundation announced 17 candidates for the first Python Packaging Council election on August 13, with voting scheduled for September 1-15.
Socket researchers discovered TrapDoor, a supply chain attack spanning 34 packages and 384+ versions across three registries, with a novel technique that embeds hidden instructions in AI coding assistant config files to trigger credential exfiltration.
Nine days after v0.13 closed Hermes Agent's durability gap, Nous Research shipped v0.14 on May 16 — adding pip install from PyPI, native Windows, and a local OpenAI-compatible proxy that wraps Claude Pro, ChatGPT Pro, and SuperGrok subscriptions.
TeamPCP's May 11 supply-chain attack abused a pull_request_target workflow, GitHub Actions cache poisoning, and OIDC token theft to ship 84 malicious TanStack versions and spread to Mistral AI, UiPath and others.
PEP 772 was accepted on April 16, 2026, establishing an elected five-member Python Packaging Council with authority over standards covering pip, setuptools, and PyPI.
Attackers published lightning 2.6.2 and 2.6.3 to PyPI on April 30, executing an obfuscated JavaScript payload to harvest cloud credentials from anyone who imported the package. Maintainers quarantined the malicious builds within 42 minutes.
Threat actor TeamPCP used credentials stolen in the Trivy compromise to backdoor LiteLLM versions 1.82.7 and 1.82.8 on PyPI, deploying a multi-stage credential stealer across an estimated 500,000 environments.
An audit of the world's largest open source package registries finds they spend 12 percent of their budgets fighting malware and just 2 percent on new features, with no path to sustainable security funding.