A campaign targeted GitHub Actions to steal PyPI tokens—PyPI wasn’t compromised and no PyPI packages were published by the attackers. Stay safe: review your tokens, rotate any exposed ones, and use short-lived, scoped GitHub Actions tokens. Details:
https://blog.pypi.org/posts/2025-09-16-github-actions-token-exfiltration/
If you have a fediverse account, you can quote this note from your own instance. Search https://fosstodon.org/users/pypi/statuses/115270663510354143 on your instance and quote it. (Note that quoting is not supported in Mastodon.)
