PyPI announces mandatory use of 2FA for all software publishers
Summary
The Python Package Index (PyPI) has announced that it will require every account that manages a project on the platform to have two-factor authentication (2FA) turned on by the end of the year. The PyPI team says the decision to make 2FA mandatory on all accounts is part of their long-term commitment to enhancing security on the platform, complementing previous measures taken in that direction, like blocking compromised credentials and supporting API tokens. Additionally, the Python project repository has suffered from rampant malware uploads, famous package impersonation, and the re-submission of malicious code using hijacked accounts in the past months. The problem reached such a magnitude that PyPI last week had to temporarily pause registrations of new users and projects until an effective defense solution could be developed and implemented. In the following months, impacted users are recommended to prepare and enable the additional security measure using either a hardware key or an authentication app.