What we found PyPI keeps showing up in supply chain attacks, usually as the place malicious packages get published. That made us curious about the credentials already sitting in the open.

What we found PyPI keeps showing up in supply chain attacks, usually as the place malicious packages get published. That made us curious about the credentials already sitting in the open.