PyPI: Preventing Domain Resurrection Attacks

3 miketheman 1 8/18/2025, 4:27:23 PM blog.pypi.org ↗

Comments (1)

miketheman · 2h ago
PyPI now checks for expired domains to prevent domain resurrection attacks, a type of supply-chain attack where someone buys an expired domain and uses it to take over PyPI accounts through password resets.