A follow-up to the previous post . We have since learned that the campaign was orchestrated by the company that owns the inbox.ru email domain, and not by a malicious third party as we initially suspected. Following the previous post, a representative of the parent company for inbox.ru reached out to PyPI Admins to discuss the situation.