Supply-chain attacks on open source software are getting out of hand
Malicious packages published on npm and PyPI had been downloaded more than 56,000 times, containing malware that enabled keylogging and other surveillance functionalities.
Episode #258: Supporting the Python Package Index - The Real Python Podcast
Supporting over 650,000 projects on the Python Package Index involves tackling user issues and enhancing community engagement through varied support roles.