Security research uncovered 3,714 unique PyPI tokens leaked on GitHub and Docker Hub, of which 62 remained live, exposing 125 packages with roughly 25,000 monthly downloads to potential supply chain attacks. PyPI revoked the credentials and built new admin tooling for disclosures.