Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
PyPI Restricts Older Release File Uploads to Boost Security

PyPI Restricts Older Release File Uploads to Boost Security

Posted on July 27, 2026 By CWS

The Python Package Index (PyPI) has implemented a significant security measure to prevent malicious file uploads to existing package versions. With this new policy, uploads of new files to package releases older than 14 days are now restricted. This step is aimed at thwarting potential attacks where compromised tokens or workflows could be exploited to add harmful files to established Python packages.

Understanding the New Policy

As of July 8, 2022, PyPI’s Warehouse codebase enforces a rule that blocks uploads for any release older than two weeks. This change addresses a critical software supply-chain vulnerability by eliminating “open-ended” release possibilities. Previously, package maintainers enjoyed the flexibility of updating files for an existing release at any given time.

While this capability was beneficial for improving compatibility with new Python versions, it also posed a security risk. Attackers gaining access to API tokens or CI/CD pipelines could exploit this flexibility to introduce malicious files without altering the version number. This made detecting compromised packages during standard updates particularly challenging.

Impact and Rationale

PyPI has stated that, to its knowledge, this specific vulnerability has not been exploited by attackers in the past. However, the absence of technical barriers meant it remained a latent risk. The importance of the new rule was underscored by incidents involving popular packages like LiteLLM and Telnyx, which demonstrated the potential for supply-chain attacks.

With the new restrictions, any unauthorized file additions to older releases are effectively prevented, forcing maintainers to issue a new version if they need to support newer Python releases. This change simplifies the incident response process by ensuring all files within a release are legitimate, reducing user uncertainty regarding package safety.

Community and Future Developments

Before implementing this policy, PyPI conducted an analysis of historical publishing patterns. Among the top 15,000 packages, only 56 had added files after the initial release beyond the 14-day window, indicating minimal disruption for most maintainers. The change was also discussed at the Packaging Summit during PyCon US 2022, where it received general support.

Currently, this restriction serves as a practical security measure, but PyPI advises against considering it a formal guarantee of a release’s state. The platform plans to introduce more comprehensive definitions and controls through the proposed Upload 2.0 API and PEP 694, which will provide clearer semantics around open and closed releases.

This proactive step by PyPI significantly mitigates the risk of package poisoning, ensuring a safer environment for Python developers globally.

Cyber Security News Tags:API security, Cybersecurity, developer security, file uploads, package management, package security, PyPI, Python packages, software supply chain, supply chain attacks

Post navigation

Previous Post: Critical ChatGPT AgentForger Exploit Fixed by OpenAI
Next Post: TELESHIM Exploits Telegram for C2 in Middle East Attacks

Related Posts

Turla Hackers Exploit SharePoint Vulnerability in France Turla Hackers Exploit SharePoint Vulnerability in France Cyber Security News
Chaos Ransomware Exploits Browsers as Secret Command Channels Chaos Ransomware Exploits Browsers as Secret Command Channels Cyber Security News
Five Hackers Behind Notorious Data Selling Platform BreachForums Arrested Five Hackers Behind Notorious Data Selling Platform BreachForums Arrested Cyber Security News
MacOS Users Targeted by Infiniti Stealer Malware MacOS Users Targeted by Infiniti Stealer Malware Cyber Security News
North Korean Hackers Weaponizing NPM Packages to Steal Cryptocurrency and Sensitive Data North Korean Hackers Weaponizing NPM Packages to Steal Cryptocurrency and Sensitive Data Cyber Security News
China-Aligned APT Hackers Exploit Windows Group Policy to Deploy Malware China-Aligned APT Hackers Exploit Windows Group Policy to Deploy Malware Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • SparkKitty Targets Crypto Users via Photo Scanning
  • DentaQuest Data Breach Affects Millions Nationwide
  • TELESHIM Exploits Telegram for C2 in Middle East Attacks
  • PyPI Restricts Older Release File Uploads to Boost Security
  • Critical ChatGPT AgentForger Exploit Fixed by OpenAI

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • SparkKitty Targets Crypto Users via Photo Scanning
  • DentaQuest Data Breach Affects Millions Nationwide
  • TELESHIM Exploits Telegram for C2 in Middle East Attacks
  • PyPI Restricts Older Release File Uploads to Boost Security
  • Critical ChatGPT AgentForger Exploit Fixed by OpenAI

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark