
Security researchers from Israeli cybersecurity firm Check Point have discovered ten malicious packages on the Python Package Index (PyPI), a public code repository of software for the Python programming language used by Python developers.
The malicious packages have been removed from PyPI for their ability to harvest critical data points such as passwords and API tokens. They could install info-stealers that enable attackers to steal the developer’s private data and personal credentials.
The offending packages include:
Once the security researchers identified these malicious users and packages, they reportedly alerted PyPI via their official website. Following the disclosure, PyPI removed these packages, the advisory concluded.
Notably, several malicious open-source packages have previously been discovered on the PyPI repository. The JFrog Security research team found 11 new malware packages in November 2021 that had received over 40,000 downloads from PyPI. In July, the PyPI repository’s team began enforcing the two-factor authentication (2FA) policy for projects labeled as “critical” to decrease the number of malicious packages on the platform.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543