I made a thing, a soundscape based on #PyPI package data feed updates ๐ŸŽถ๐Ÿ๐Ÿ“ฆ๐ŸŽถ

Maybe you'll enjoy it too?
https://miketheman.github.io/listen-to-pypi/

Listen to PyPI - Hear the Python Package Index in real-time

Every PyPI package release becomes a sound and a glowing circle. An ambient soundscape driven by real-time Python community activity, by miketheman.

Listen to PyPI

Beep, Beep - I am your friendly #Snakemake release announcement bot.

There is a new release of the ๐’๐ง๐š๐ค๐ž๐ฆ๐š๐ค๐ž ๐„๐ฑ๐ž๐œ๐ฎ๐ญ๐จ๐ซ ๐๐ฅ๐ฎ๐ ๐ข๐ง ๐Ÿ๐จ๐ซ ๐’๐‹๐”๐‘๐Œ systems. Its version now is 2.6.1!

Give us some time, and you will automatically find the plugin on #Bioconda and #Pypi.

This plugin is relevant for #HPC users using the #SLURM batch system.
The maintainers are here on Mastodon -
@rupdecat and @johanneskoester.

If you discover any issues, please report them on https://github.com/snakemake/snakemake-executor-plugin-slurm/issues.

See https://github.com/snakemake/snakemake-executor-plugin-slurm/releases/tag/v2.6.1 for details. Here is the header of the changelog:
๐‘…๐‘’๐‘™๐‘’๐‘Ž๐‘ ๐‘’ ๐‘๐‘œ๐‘ก๐‘’๐‘  (๐‘๐‘œ๐‘ ๐‘ ๐‘–๐‘๐‘™๐‘ฆ ๐‘Ž๐‘๐‘๐‘Ÿ๐‘–๐‘”๐‘’๐‘‘):
๐๐ฎ๐  ๐…๐ข๐ฑ๐ž๐ฌ

* code refactoring: https://github.com/snakemake/snakemake-executor-plugin-slurm/issues/451
* handle integer slurm_account values from YAML parsing: https://github.com/snakemake/snakemake-executor-plugin-slurm/issues/448

The PSF is looking for a PyPI Sustainability Engineer to join the team! This is a full time, 1-year contract (with the possibility of renewal), globally remote position. If you love #Python, care about open source, and want your work to matter at infrastructure scaleโ€“consider applying! Please boost this post and share with your colleagues and networks. #PyPI #Python

https://pythonsoftwarefoundation.applytojob.com/apply/xz5k3X31UQ/Sustainability-Engineer-PyPI
https://pythonsoftwarefoundation.applytojob.com/apply/xz5k3X31UQ/Sustainability-Engineer-PyPI

Sustainability Engineer, PyPI - Career Page

Apply to Sustainability Engineer, PyPI in Remote.

๐Ÿ”Ž๐Ÿ” #PyPI has completed its second external #security audit! Thanks to @sovtechfund for funding, @trailofbits for the audit, and Alpha-Omega for supporting rapid remediation. Find the full report on the Trail of Bits publication page. #Python
https://blog.pypi.org/posts/2026-04-16-pypi-completes-second-audit/
PyPI has completed its second audit - The Python Package Index Blog

We are proud to announce PyPI's second external security audit.

This website accuses common libraries of being hit by malware attacks without substantiating evidence.

Couldn't find reports of #orjson being highjacked, just this websites assertion.

The same website calls my apps vulnerable and malicious, also, doesn't exactly say why.

#pypi #supplychain

https://secure.software/pypi/packages/orjson

orjson - PyPI | ReversingLabs Spectra Assure Community

Supply chain risk analysis for orjson. Learn more about package security, deployment risks, vulnerabilities, popularity, versions, and more with ReversingLabs.

Publish #Python packages to #PyPI using a trusted publisher is a nice move, but I hope there will be more official trusted publishers in a near future.

https://406.ch/writing/switching-all-of-my-python-packages-to-pypi-trusted-publishing/

Switching all of my Python packages to PyPI trusted publishing - Matthias Kestenholz

Fake recruiter campaign targets crypto developers with RAT

A sophisticated fake recruitment campaign named 'graphalgo' has been active since May 2025, targeting JavaScript and Python developers in the cryptocurrency sector. Attackers approach victims through LinkedIn, Facebook, and Reddit with fabricated job opportunities from fake blockchain companies like Veltrix Capital. The campaign uses malicious dependencies hidden in npm and PyPI packages, delivered through coding test repositories on GitHub. Notable is the bigmathutils package that accumulated over 10,000 downloads before its malicious version was released. The operation deploys a remote access trojan (RAT) with token-protected C2 communication, file manipulation capabilities, and functionality to detect the Metamask browser extension, indicating focus on cryptocurrency theft. The modular campaign design allows threat actors to maintain backend infrastructure while easily replacing compromised frontend elements.

Pulse ID: 69dd073f50edefa3e44adec6
Pulse Link: https://otx.alienvault.com/pulse/69dd073f50edefa3e44adec6
Pulse Author: AlienVault
Created: 2026-04-13 15:09:51

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#BlockChain #Browser #CyberSecurity #Facebook #GitHub #InfoSec #Java #JavaScript #LinkedIn #NPM #OTX #OpenThreatExchange #PyPI #Python #RAT #RemoteAccessTrojan #Trojan #bot #cryptocurrency #developers #AlienVault

LevelBlue - Open Threat Exchange

Learn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.

LevelBlue Open Threat Exchange
North Koreaโ€™s Contagious Interview Campaign Spreads Across 5 Ecosystems, Delivering Staged RAT Payloads
#ContagiousInterview #npm #PyPI #Packagist
https://socket.dev/blog/contagious-interview-campaign-spreads-across-5-ecosystems
North Koreaโ€™s Contagious Interview Campaign Spreads Across 5...

Malicious packages published to npm, PyPI, Go Modules, crates.io, and Packagist impersonate developer tooling to fetch staged malware, steal credentia...

Socket

Il colloquio di lavoro come arma: Lazarus Group e la campagna Graphalgo contro gli sviluppatori crypto

Da maggio 2025, Lazarus Group conduce la campagna Graphalgo: 192 pacchetti npm e PyPI malevoli distribuiti tramite finti colloqui di lavoro tecnici per sviluppatori blockchain. Il malware a tre stadi punta direttamente ai wallet MetaMask. Un'operazione di cyberspionaggio e furto crypto a firma nordcoreana tuttora attiva.

https://insicurezzadigitale.com/il-colloquio-di-lavoro-come-arma-lazarus-group-e-la-campagna-graphalgo-contro-gli-sviluppatori-crypto/