Read the follow-up post: Phishing Attack Follow-Up (Ongoing, preliminary report) PyPI has not been hacked, but users are being targeted by a phishing attack that attempts to trick them into logging in to a fake PyPI site. Over the past few days, users who have published projects on PyPI with their email in package metadata may have received an email titled: [PyPI] Email verification from the email address noreply@pypj.org . Note the lowercase j in the domain name, which is not the official PyPI domain, pypi.org .