HomeUpdatesPyPI: Announces mandatory use of 2FA for all software publishers

PyPI: Announces mandatory use of 2FA for all software publishers

The Python Package Index (PyPI) has announced that, by the end of the year, every account managing a project on the platform will need to have two-factor authentication (2FA) enabled.

See also: Malicious PyPi packages contained W4SP Stealer malware

PyPI 2FA

PyPI is a software repository for packages created using the Python programming language. It hosts approximately 200,000 packages, allowing developers to quickly find existing packages that meet the various requirements of their projects, thus saving time and effort.

See also: PyPi python packages steal crypto via Chrome extensions

The PyPI team states that the decision to make two-factor authentication mandatory on all accounts is part of its long-term commitment to strengthening security on the platform, complementing previous steps taken in this direction, such as blocking compromised credentials and supporting API tokens.

One benefit of two-factor authentication (2FA) protection is the reduced risk of supply chain attacks. These types of attacks occur when a malicious actor gains control of a software maintainer's account and adds a backdoor or malware to a package used as a dependency in various software projects.

Depending on how popular the package is, such attacks can affect millions of users. While developers are responsible for thoroughly inspecting the building blocks of their projects, PyPI's measures should make it easier to minimize these types of problems.

Additionally, the Python project repository has been hit by rampant malware uploads and resubmission of malicious code using hijacked accounts in recent months.

The problem reached such a magnitude that last week, PyPI was forced to temporarily suspend new user and project registrations until an effective defense solution could be developed and implemented.

Two-factor authentication protection will help mitigate the problem of account takeover attacks and should also place a limit on the number of new accounts a suspended user can create to reload malicious packages.

See also: Yet another PyPI package installs malware

PyPI: Announces mandatory use of 2FA for all software publishers

The road to 2FA

The requirement to set up 2FA on all project and organization maintainer accounts is due by the end of 2023.

In the coming months, affected users are advised to set up and enable the additional security measure using either a hardware key or an authentication app.

The PyPI team says that the preparatory work it has done in previous months, such as the introduction of “Trusted Publishing,” combined with parallel initiatives from platforms like GitHub that have helped developers familiarize themselves with 2FA requirements, makes this year a great time to introduce the measure.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS