We take security very seriously and ask that you follow our security policy carefully.
Important! If you believe you've identified a security issue with PyPI, DO NOT report the issue in any public forum, including (but not limited to):
Login to your PyPI account, then visit the project's page on PyPI. At the bottom of the sidebar, click Report project as malware. Supply the following details in the form:
Valid malware reports may include examples of typo-squatting, dependency confusion, data exfiltration, obfuscation, command/control, etc.
Email security@pypi.org, providing as much relevant information as possible, including reproducing steps.
Once you've submitted an issue via email, you should receive an acknowledgment within 48 hours.
Depending on the action to be taken, you may receive further follow-up emails.
This security policy was last updated on March 2024.