Hacker News new | ask | show | jobs
by ptx 39 days ago
It's probably a better idea to follow the process documented in PEP 541 [1] and contact the PyPI admins to request a transfer of the name. Taking over the domain to impersonate the original owner would look indistinguishable from a supply-chain attack.

[1] https://peps.python.org/pep-0541/#how-to-request-a-name-tran...

1 comments

Yeah, I noticed this library few years ago when checking pypi.org for supply chain attack vulnerability and scanned all libraries. There are a lot of such libraries which you can take over.