{"id":52176,"date":"2023-06-02T20:39:00","date_gmt":"2023-06-02T20:39:00","guid":{"rendered":"https:\/\/www.darkreading.com\/application-security\/pypi-2fa-requirements-dont-go-far-enough"},"modified":"2023-06-02T20:39:00","modified_gmt":"2023-06-02T20:39:00","slug":"pypis-2fa-requirements-dont-go-far-enough-researchers-say","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/pypis-2fa-requirements-dont-go-far-enough-researchers-say\/","title":{"rendered":"PyPI&#8217;s 2FA Requirements Don&#8217;t Go Far Enough, Researchers Say"},"content":{"rendered":"<div><img decoding=\"async\" src=\"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/bltf34e8fb49828a01d\/647a4b3565658f7bbb22a892\/python-Ernie_Janes-Alamy.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<p>The official open source code repository for the Python programming language, the Python Package Index (PyPI), will require all user accounts to enable two-factor authentication (2FA) by the end of 2023.<\/p>\n<p>The security move may help prevent cyberattackers from compromising maintainer accounts and injecting malicious code into existing legitimate projects, but it&#8217;s not a silver bullet when it comes to shoring up overall software supply chain security, researchers warn.<\/p>\n<p>&#8220;Between now and the end of the year, PyPI will begin gating access to certain site functionality based on 2FA usage,&#8221; explained PyPI administrator and maintainer Donald Stufft, in a <a href=\"https:\/\/blog.pypi.org\/posts\/2023-05-25-securing-pypi-with-2fa\/\" target=\"_blank\" rel=\"noopener\">recent blog posting<\/a>. &#8220;In addition, we may begin selecting certain users or projects for early enforcement.&#8221;<\/p>\n<p>To implement 2FA, package maintainers have the option to use a security token or other hardware device, or an authentication app; and Stufft said that users are encouraged to switch to using either <a href=\"https:\/\/blog.pypi.org\/posts\/2023-04-20-introducing-trusted-publishers\/#:~:text=PyPI%20currently%20supports%20trusted%20publishing,their%20support%20for%20OpenID%20Connect.&amp;text=Using%20the%20PyPA's%20GitHub%20action,are%20available%20in%20our%20documentation.\" target=\"_blank\" rel=\"noopener\">PyPI&#8217;s Trusted Publishers<\/a> feature or API tokens to upload code to PyPI.<\/p>\n<h2 class=\"regular-text\">Stemming PyPI&#8217;s Malicious Package Activity<\/h2>\n<p>The announcement comes amidst a slew of attacks by cybercriminals looking to infiltrate various software programs and apps with malware that can then go on to be widely disseminated. Since PyPI and <a href=\"https:\/\/www.darkreading.com\/application-security\/once-again-malware-discovered-hidden-in-npm\" target=\"_blank\" rel=\"noopener\">other repositories like npm<\/a> and GitHub house the building blocks that developers use to build those offerings, compromising their contents is a great way to do that.<\/p>\n<p>Researchers say that 2FA in particular (which <a href=\"https:\/\/www.darkreading.com\/dr-tech\/github-expands-secret-scanning-2fa-across-platform\" target=\"_blank\" rel=\"noopener\">GitHub also recently implemented<\/a>) will help prevent developer account takeover, which is one way that bad actors get their hooks into apps.<\/p>\n<p>&#8220;We&#8217;ve seen <a href=\"https:\/\/www.darkreading.com\/cloud\/phishing-campaign-targets-pypi-users-to-distribute-malicious-code\" target=\"_blank\" rel=\"noopener\">phishing attacks launched<\/a> against the project maintainers for commonly used PyPI packages that are intended to compromise those accounts,&#8221; says Ashlee Benge, director of threat intelligence advocacy at ReversingLabs. &#8220;Once compromised, those accounts can easily be used to push malicious code to the PyPI project in question.&#8221;<\/p>\n<p>One of the most likely scenarios of initial infection would be a developer accidentally installing a malicious package, for example, typing a Python install command by mistake, says Dave Truman, vice president of cyber-risk at Kroll.<\/p>\n<p>&#8220;A lot of the malicious packages contain functionality for stealing credentials or browser session cookies and are coded to run on the malicious package being installed,&#8221; he explains. &#8220;At this point, the malware would steal their credentials and sessions which could possibly include logins usable with PyPI. In other words \u2026 one developer could allow the actor to pivot to <a href=\"https:\/\/www.darkreading.com\/application-security\/solarwinds-faces-potential-sec-enforcement-act-over-orion-breach\" target=\"_blank\" rel=\"noopener\">a major supply chain attack<\/a> depending on what that developer has access to \u2014 2FA on PyPI would help stop the actor taking advantage of [that].&#8221;<\/p>\n<h2 class=\"regular-text\">More Software Supply Chain Security Work to Do<\/h2>\n<p>ReversingLabs&#8217; Benge notes that while PyPI&#8217;s 2FA requirements are a step in the right direction, more security layers are needed to really lock down the software supply chain. That&#8217;s because one of the most common ways that cybercriminals leverage software repositories is by <a href=\"https:\/\/www.darkreading.com\/application-security\/novel-pypi-malware-compiled-python-bytecode-evade-detection\" target=\"_blank\" rel=\"noopener\">uploading their own malicious packages<\/a> in hopes of duping developers into pulling them into their software.<\/p>\n<p>After all, anyone can sign up for a PyPI account, no questions asked.<\/p>\n<p>These efforts usually involve mundane social-engineering tactics, she says: &#8220;<a href=\"https:\/\/www.darkreading.com\/attacks-breaches\/solarwinds-attackers-gearing-up-typosquatting-attacks\" target=\"_blank\" rel=\"noopener\">Typosquatting is common<\/a> \u2014 for example, naming a package &#8216;djanga&#8217; (containing malicious code) versus &#8216;django&#8217; (the legitimate and commonly used library).&#8221;<\/p>\n<p>Another tactic is to hunt for abandoned projects to bring back to life. &#8220;A formerly benign project is abandoned, removed, and then repurposed for hosting malware, <a href=\"https:\/\/www.reversinglabs.com\/blog\/package-names-repurposed-to-push-malware-on-pypi\" target=\"_blank\" rel=\"noopener\">like with termcolour<\/a>,&#8221; she explains. This recycling approach offers malicious actors the benefit of using the former project&#8217;s legitimate reputation to lure in developers.<\/p>\n<p>&#8220;Adversaries are continually figuring out multiple ways to <a href=\"https:\/\/www.darkreading.com\/application-security\/10-malicious-packages-slither-pypi-registry\" target=\"_blank\" rel=\"noopener\">get developers to use malicious packages<\/a>, which is why it&#8217;s critical for Python and other programming languages with software repositories like PyPi to have a comprehensive software supply chain approach to security,&#8221; says Javed Hasan, CEO and co-founder, Lineaje.<\/p>\n<p>Also, there are multiple ways to defeat 2FA, Benge notes, including <a href=\"https:\/\/www.darkreading.com\/threat-intelligence\/cybercriminals-target-telecom-provider-networks\" target=\"_blank\" rel=\"noopener\">SIM swapping<\/a>, OIDC exploitation, and session hijacking. While these tend to be labor intensive, motivated attackers will still go to the trouble of trying to work around MFA and certainly 2FA, she says.<\/p>\n<p>&#8220;Such attacks require much higher levels of engagement by attackers and many additional steps that will deter less motivated threat actors, but compromising an organization&#8217;s supply chain offers a potentially huge payoff for threat actors, and many may decide that the extra effort is worth it,&#8221; she says.<\/p>\n<p>While repositories take steps to make their environments safer, organizations and developers need to take their own precautions, Hasan counsels.<\/p>\n<p>&#8220;Organizations need modern supply chain tamper detection tools that help companies break down what&#8217;s in their software and avoid deployment of unknown and dangerous components,&#8221; he says. Also, efforts like <a href=\"https:\/\/www.darkreading.com\/dr-tech\/waiting-for-sbom-take-a-look-at-asm\" target=\"_blank\" rel=\"noopener\">software bills of materials (SBOMs)<\/a> and <a href=\"https:\/\/www.darkreading.com\/dr-tech\/exposure-management-understanding-the-attacker-takes-center-stage\" target=\"_blank\" rel=\"noopener\">attack surface management<\/a> can help.<\/p>\n<p>Read More <a href=\"https:\/\/www.darkreading.com\/application-security\/pypi-2fa-requirements-dont-go-far-enough\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Python Package Index will require developers to better secure their accounts as cyberattacks ramp up, but protecting the software supply chain will take more than that.Read More <a href=\"https:\/\/www.darkreading.com\/application-security\/pypi-2fa-requirements-dont-go-far-enough\">HERE<\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[151],"tags":[],"class_list":["post-52176","post","type-post","status-publish","format-standard","hentry","category-darkreading-ti"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>PyPI&#039;s 2FA Requirements Don&#039;t Go Far Enough, Researchers Say 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/pypis-2fa-requirements-dont-go-far-enough-researchers-say\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"PyPI&#039;s 2FA Requirements Don&#039;t Go Far Enough, Researchers Say 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/pypis-2fa-requirements-dont-go-far-enough-researchers-say\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2023-06-02T20:39:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/bltf34e8fb49828a01d\/647a4b3565658f7bbb22a892\/python-Ernie_Janes-Alamy.jpg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/pypis-2fa-requirements-dont-go-far-enough-researchers-say\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/pypis-2fa-requirements-dont-go-far-enough-researchers-say\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"PyPI&#8217;s 2FA Requirements Don&#8217;t Go Far Enough, Researchers Say\",\"datePublished\":\"2023-06-02T20:39:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/pypis-2fa-requirements-dont-go-far-enough-researchers-say\\\/\"},\"wordCount\":804,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/pypis-2fa-requirements-dont-go-far-enough-researchers-say\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/eu-images.contentstack.com\\\/v3\\\/assets\\\/blt66983808af36a8ef\\\/bltf34e8fb49828a01d\\\/647a4b3565658f7bbb22a892\\\/python-Ernie_Janes-Alamy.jpg\",\"articleSection\":[\"DarkReading |TI\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/pypis-2fa-requirements-dont-go-far-enough-researchers-say\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/pypis-2fa-requirements-dont-go-far-enough-researchers-say\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/pypis-2fa-requirements-dont-go-far-enough-researchers-say\\\/\",\"name\":\"PyPI's 2FA Requirements Don't Go Far Enough, Researchers Say 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/pypis-2fa-requirements-dont-go-far-enough-researchers-say\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/pypis-2fa-requirements-dont-go-far-enough-researchers-say\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/eu-images.contentstack.com\\\/v3\\\/assets\\\/blt66983808af36a8ef\\\/bltf34e8fb49828a01d\\\/647a4b3565658f7bbb22a892\\\/python-Ernie_Janes-Alamy.jpg\",\"datePublished\":\"2023-06-02T20:39:00+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/pypis-2fa-requirements-dont-go-far-enough-researchers-say\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/pypis-2fa-requirements-dont-go-far-enough-researchers-say\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/pypis-2fa-requirements-dont-go-far-enough-researchers-say\\\/#primaryimage\",\"url\":\"https:\\\/\\\/eu-images.contentstack.com\\\/v3\\\/assets\\\/blt66983808af36a8ef\\\/bltf34e8fb49828a01d\\\/647a4b3565658f7bbb22a892\\\/python-Ernie_Janes-Alamy.jpg\",\"contentUrl\":\"https:\\\/\\\/eu-images.contentstack.com\\\/v3\\\/assets\\\/blt66983808af36a8ef\\\/bltf34e8fb49828a01d\\\/647a4b3565658f7bbb22a892\\\/python-Ernie_Janes-Alamy.jpg\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/pypis-2fa-requirements-dont-go-far-enough-researchers-say\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"PyPI&#8217;s 2FA Requirements Don&#8217;t Go Far Enough, Researchers Say\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"PyPI's 2FA Requirements Don't Go Far Enough, Researchers Say 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/pypis-2fa-requirements-dont-go-far-enough-researchers-say\/","og_locale":"en_US","og_type":"article","og_title":"PyPI's 2FA Requirements Don't Go Far Enough, Researchers Say 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/pypis-2fa-requirements-dont-go-far-enough-researchers-say\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2023-06-02T20:39:00+00:00","og_image":[{"url":"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/bltf34e8fb49828a01d\/647a4b3565658f7bbb22a892\/python-Ernie_Janes-Alamy.jpg","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/pypis-2fa-requirements-dont-go-far-enough-researchers-say\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/pypis-2fa-requirements-dont-go-far-enough-researchers-say\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"PyPI&#8217;s 2FA Requirements Don&#8217;t Go Far Enough, Researchers Say","datePublished":"2023-06-02T20:39:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/pypis-2fa-requirements-dont-go-far-enough-researchers-say\/"},"wordCount":804,"commentCount":0,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/pypis-2fa-requirements-dont-go-far-enough-researchers-say\/#primaryimage"},"thumbnailUrl":"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/bltf34e8fb49828a01d\/647a4b3565658f7bbb22a892\/python-Ernie_Janes-Alamy.jpg","articleSection":["DarkReading |TI"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.threatshub.org\/blog\/pypis-2fa-requirements-dont-go-far-enough-researchers-say\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/pypis-2fa-requirements-dont-go-far-enough-researchers-say\/","url":"https:\/\/www.threatshub.org\/blog\/pypis-2fa-requirements-dont-go-far-enough-researchers-say\/","name":"PyPI's 2FA Requirements Don't Go Far Enough, Researchers Say 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/pypis-2fa-requirements-dont-go-far-enough-researchers-say\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/pypis-2fa-requirements-dont-go-far-enough-researchers-say\/#primaryimage"},"thumbnailUrl":"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/bltf34e8fb49828a01d\/647a4b3565658f7bbb22a892\/python-Ernie_Janes-Alamy.jpg","datePublished":"2023-06-02T20:39:00+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/pypis-2fa-requirements-dont-go-far-enough-researchers-say\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/pypis-2fa-requirements-dont-go-far-enough-researchers-say\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/pypis-2fa-requirements-dont-go-far-enough-researchers-say\/#primaryimage","url":"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/bltf34e8fb49828a01d\/647a4b3565658f7bbb22a892\/python-Ernie_Janes-Alamy.jpg","contentUrl":"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/bltf34e8fb49828a01d\/647a4b3565658f7bbb22a892\/python-Ernie_Janes-Alamy.jpg"},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/pypis-2fa-requirements-dont-go-far-enough-researchers-say\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"PyPI&#8217;s 2FA Requirements Don&#8217;t Go Far Enough, Researchers Say"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/52176","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=52176"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/52176\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=52176"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=52176"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=52176"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}