~/TechPurAI
~/news/pypi-mandatory-2fa-all-maintainers
PyPI now requires two-factor authentication for every maintainer account
Python

PyPI now requires two-factor authentication for every maintainer account

PyPI has expanded mandatory two-factor authentication to cover every account with package-upload permissions, closing the gap left by the previous policy, which only required 2FA for maintainers of the most-downloaded projects. Accounts without 2FA enabled will lose upload access until they enroll.

Why now

The policy follows several real incidents this year where attackers compromised maintainer accounts on mid-sized packages — ones popular enough to be worth targeting, but below the download threshold that triggered the earlier mandatory-2FA tier — and pushed malicious versions that were downloaded before detection.

Why it matters

If you maintain any package on PyPI, regardless of its download count, this is not optional starting now — check your account's 2FA status before your next release, since a lapsed upload permission mid-release is a worse time to discover this than now.

For consumers of packages, not just maintainers

This doesn't retroactively secure packages already compromised in past incidents, but it meaningfully raises the cost of the most common attack pattern — a phished or reused maintainer password — going forward. Pinning dependencies and reviewing lockfile diffs on upgrade remains the practical mitigation on the consuming side; 2FA reduces how often that diff has something malicious in it to catch.

Source: blog.pypi.org

VK

Vijay Kumar

Founder of TechPurAI — writing hands-on tutorials and honest tool breakdowns.

LinkedIn ↗

More news

Samsung's Galaxy Event draws final coverage ahead of tomorrow's revealAug 26, 2026Realme P4s 5G launches in India with a 144Hz AMOLED display and IP69 ratingAug 26, 2026OpenAI's Jalapeño chip benchmarks resurface as Nvidia reports earningsAug 26, 2026