If indeed the problem is pushing malicious code and publishing directly to PyPi itself, there's only one listed account owner (though there could be more): Glenn Jocher. Email listed directly on PyPi. If someone got access to this email, you could search for it inside infostealer or breach databases
1 likes 1 replies
?