PyPI ecosystem

PyPI package security

In short

A PyPI source distribution can execute code while it installs, not when you import it. Extuno analyzes wheels and sdists, then runs that install path in a sandbox. It flags install-time code execution, typosquatted names, and updates that turn malicious.

What makes PyPI packages risky?

A source distribution runs setup.py during installation, so the code executes before anything imports the package. Typosquatting is how an attacker gets into that install path. One wrong character in a requirements file and the payload runs with the rest of the install.

What does Extuno check on PyPI?

Install-time code execution, network calls and credential reads during install, obfuscated payloads, typosquatting of popular package names, and the poisoned-update pattern across versions.

How does the sandbox handle setup.py?

Extuno runs the install in an ephemeral, network-segmented micro-VM and records process, network, and file behavior, so a malicious setup.py is observed with its endpoint and payload instead of running on your machine.

FAQ

Common questions

Can a PyPI package run code on install?
Yes. A source distribution's setup.py executes during installation, which is why install-time analysis matters as much as reading the source.
Does Extuno cover both wheels and sdists?
Yes. It analyzes wheels and source distributions, and runs the install path in a sandbox to capture setup.py behavior.