There's a nasty worm going around named Shai-Hulud. It's also capable of exposing some projects' long-lived PyPI API Tokens. Read more on what's happening, and what you can do to protect your projects.

TL,DR: Adopt Trusted Publishing ๐Ÿ”๐Ÿš€๐Ÿ“ฆ

blog.pypi.org/posts/2025-11-26

0
0
1

If you have a fediverse account, you can quote this note from your own instance. Search https://hachyderm.io/users/miketheman/statuses/115618016841703831 on your instance and quote it. (Note that quoting is not supported in Mastodon.)

0