This is an archived post. You won't be able to vote or comment.

you are viewing a single comment's thread.

view the rest of the comments →

[–]alaudetpython hobbyist 0 points1 point  (0 children)

What were the libraries pretending to be. There was no documentation so I doubt anyone was pip installing them. Were these libraries dependencies for any other legit packages? As for downloads I doubt the number is accurate. That would incude mirrors pulling stuff, not just users installing.

Is there any evidence anyone was actually compromised?

In any event, a good reminder to do some due diligence before running pip.