PyPI Explores Prefix Reservation for Organizations Under PEP 752 to Prevent Name Squatting
PyPI is considering a mechanism to reserve package name prefixes for organizations following the adoption of PEP 752 in June 2026. The proposal aims to link recognizable prefixes such as google-cloud-, opentelemetry-, and apache-airflow-providers- to verified owners, reducing the risk of name squatting and dependency confusion attacks.
Currently, PyPI treats all package names as independent entries in a flat namespace. Organizations like yandex-bot and seznam-bot have published hundreds of placeholder packages to protect prefixes, yet any user can still register new names that begin with familiar strings. PEP 752 introduces implicit namespaces so that control over a prefix automatically covers future packages matching the normalized name pattern.
Normalization rules mean that google.cloud.storage would fall under a reserved google-cloud- prefix, while google-cloudstorage would not. Projects matching an existing prefix but published by unauthorized accounts would receive a 409 Conflict error on upload. Existing packages retain the ability to publish new versions under grandfathering rules.
Data from CodeScoring covering more than 800,000 active projects reveals that no examined prefix belongs to a single owner. The aws- prefix is controlled by 743 accounts, google- by 484, and types- by 68. Even within narrower prefixes such as datasette-, multiple independent maintainers publish plugins.
The upcoming PEP 755 will define the application process. Only organization accounts may apply, prefixes must exceed three characters and already be in use by the applicant, and overly generic terms will be rejected. Large open-source projects, universities, and government entities may receive fee waivers, while paid organizations could receive faster review.
Unlike npm scoped packages, the Python approach keeps the flat namespace intact to avoid breaking existing tooling and dependency files. New metadata will allow clients and corporate proxies to enforce prefix ownership policies once support is added.
Related articles
AI Model Hallucinations Fuel Slopsquatting Attacks on PyPI and npm Registries
Researchers identified 139 package names consistently hallucinated by five different AI models across Python and JavaScript ecosystems. Seven of these names are already registered on PyPI and npm, including one previously used to distribute malware. The attack vector, termed slopsquatting, allows attackers to register AI-suggested package names and execute code with developer privileges during installation. One package, metro-evaluator, contained malicious code removed by npm in December 2025, while another empty package css-color-stop began receiving downloads after the list was published. Real projects such as odf and lusid now occupy names that AI models recommend, causing developers to install unrelated software. Studies show hallucination rates between 4.62% and 21.7% depending on the model, with commercial models performing better than open-source ones. The findings highlight risks when AI coding agents execute dependency installation commands without human verification.
Sapper Revives Minefield to Deliver Accurate SBOM-Based Vulnerability Impact Reports for Cyber Resilience Act Compliance
Developer Perruer has forked the archived BitBom project Minefield into a new open-source tool called Sapper, fixing critical bugs in dependency graph construction and vulnerability matching. The original Minefield used roaring bitmaps and Tarjan's algorithm to build transitive dependency caches from SBOMs in O(n + m) time, but it incorrectly interpreted SPDX edge directions from protobom 0.6, creating false cycles and massively inflating dependent package counts. Additional fixes addressed SQLite memory database pooling issues, OSV range sorting errors with Go pseudo-versions and ECOSYSTEM ecosystems, and slow OSV ingestion by adding a package name index. Sapper now produces prioritized reports using CISA KEV and EPSS scores, showing exact shortest paths from vulnerable packages to root products while respecting OpenVEX statements. The tool maintains full air-gapped operation and supports CycloneDX 1.3–1.7 and SPDX 2.x formats. These improvements directly help organizations meet the 24-hour notification requirements under the EU Cyber Resilience Act for actively exploited vulnerabilities.
Fake Terraform Providers on HashiCorp Registry Distribute Go Malware to Developers
Cybersecurity researchers have identified Go-based malware distributed through two fake Terraform providers and two Go modules hosted on the official HashiCorp registry. The providers gocommunity-io/dockerd and kreuzwenker/docker, along with modules gocommunity.io/orderedbtree and gogets.dev/btreex, impersonate legitimate projects and represent the first documented case of malicious code being delivered via the HashiCorp registry. Attackers approach developers on LinkedIn, Facebook, and job forums using fake Web3 company profiles, then supply seemingly harmless repositories whose malicious behavior is triggered through npm or PyPI dependencies. Once executed, the malware collects hardware attributes, operating system data, hostname, and node availability before sending the information to attacker infrastructure. Command and control relies on a Slack channel polled every ten seconds and encrypted commands read from Sepolia testnet Ethereum smart contracts every three seconds, with each infected client using ephemeral key pairs for targeted delivery. The code matches the Graphalgo campaign previously documented by ReversingLabs and attributed to North Korean actors.
Challenges in Building Accurate SBOMs for C and C++ Projects Highlighted by CodeScoring Analysis
C and C++ ecosystems lack centralized package manifests, making SBOM generation far more complex than in Python, Java, or JavaScript. Libraries may arrive through system package managers like apt or dnf, build tools such as Conan and vcpkg, or direct source inclusion, with no single record of all components. CodeScoring’s Johnny agent uses eBPF to observe linker commands during builds and cross-references results with dpkg, RPM, and pkg-config metadata. The analysis distinguishes build-time SBOMs, which capture static libraries and compilation commands, from runtime SBOMs that reflect dynamic dependencies at execution. When version data cannot be verified, components are explicitly marked unresolved rather than guessed. The approach also addresses header-only libraries and patched artifacts that defeat simple hash matching.