Anthropic committed $1.5 million to the Python Software Foundation (PSF) under a two-year partnership to accelerate security work across the Python ecosystem, with a particular focus on reducing software supply-chain risk affecting the Python Package Index (PyPI) and the broader user base. The funding is intended to advance the PSF’s security roadmap and strengthen defenses against malicious packages and other ecosystem-level threats that can impact millions of developers and downstream organizations.
Planned work includes building automated tooling to review every package uploaded to PyPI, shifting detection from largely report-driven, after-the-fact responses toward proactive screening, and creating a dataset of known malware to support capability analysis and tool development. The effort builds on PSF’s ongoing security initiatives led by Security Developer in Residence Seth Larson and supported by PyPI Safety and Security Engineer Mike Fiedler, and is positioned as potentially reusable for other open-source package repositories beyond Python.

Trace attribution and downstream blast radius.
2 events from the most recent confirmed update back to the earliest known activity.
As part of the funded work, the PSF said it plans to build tooling to automatically review every package uploaded to PyPI rather than relying mainly on report-driven detection. The foundation also plans to create a dataset of known malware to inform capability analysis and the design of new security tools.
Anthropic entered a two-year partnership with the Python Software Foundation, committing $1.5 million to improve security across the Python ecosystem. The funding supports the PSF security roadmap, including security upgrades for CPython and PyPI aimed at reducing software supply-chain risk.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.