This makes me wonder... it's entirely possible that the PyPI people would be enthusiastic about helping to track down offenders, and their users might agree, _if they knew what the offense was_. Instead, they're presented with a typically antagonistic demand for details, so they understandably get defensive on behalf of their users. I wonder if there's not a better, less heavy-handed way to get cooperation with law enforcement when the request is reasonable.
Personally I would rather not set a precedent of handing data over to government agencies just because they ask nicely, even if it seems like it's for a mutually agreeable good cause. That is, I would rather they go through these "formal" channels, even if it seems a bit heavy-handed.
Further, whatever they're investigating here is probably "important", for some definition of important, so they likely value the ability to lean on non-disclosure clauses etc.
I wish it was that but those people would be smart enough to not use their real name when signing up - those doing supply chain attacks are often at least somewhat professional and take precautions.
I suspect it was more about going after software that was enabling piracy, those are often created by naive students who are not expecting the power of government to be unleashed on them.
> those doing supply chain attacks are often at least somewhat professional and take precautions.
Not really.
The vast majority of supply chain attacks in practice are idiots exploiting namespacing, bitflips, or typos on pypi/npm to drop miners or infostealers.
Yes, even the shit tier supply chain attacks count :)