Find Any PyPI Username with WhatsMyName App

PyPI is the package index every Python install pulls from, and maintainer identity there is a security control rather than a detail. WhatsMyName App checks whether a PyPI profile exists at a handle alongside 731 other platforms in one search.

Platform: Developer, package registry · The official package index for Python

Search PyPI Username Free

What Is PyPI and Why Username Searches Matter

The Python Package Index hosts the libraries that Python projects install by default. Every publisher has a profile at pypi.org/user/handle listing the projects they maintain, which makes maintainer identity publicly checkable by anyone reviewing a dependency.

March 2026 made the case for doing that check. Two malicious versions of litellm, 1.82.7 and 1.82.8, were published after an attacker obtained the maintainer's publishing credentials, in this case by exfiltrating a publish token from a GitHub Actions runner. The packages were live for roughly forty minutes and were downloaded more than 119,000 times before PyPI quarantined them. The payload installed a file that ran on every Python process start and stole SSH keys and cloud credentials. The same campaign, attributed to a group tracked as TeamPCP, also hit Telnyx and a widely used security scanner.

So the reasons people look up PyPI handles are practical. Engineers evaluating an unfamiliar package check whether the publisher has a history anywhere else. Security teams reviewing a dependency confirm who holds publish rights. Maintainers audit their own footprint, since a public handle is the reconnaissance step before a phishing attempt aimed at their credentials.

How PyPI Usernames Work

PyPI usernames are unique and form the profile URL at pypi.org/user/handle. The maintainer list on a project page shows the handles with publish rights, which is where you should take a handle from rather than guessing from the project name.

Project names and maintainer handles are separate things, and conflating them is how typosquatting works. A package called something familiar can be published by any handle, so the name on the tin tells you nothing about who is behind it.

Handle reuse between PyPI and GitHub is very high, since most Python projects are developed in a repository and published from it. That link is also the attack surface: the litellm compromise came through a publishing token held by automation rather than through the human account directly, which is worth remembering when you assess how a project publishes.

  • Usernames are unique across the index
  • Profile URL format: pypi.org/user/handle
  • Project names and maintainer handles are unrelated
  • Take handles from the project's maintainer list
  • High handle overlap with GitHub, and publish tokens often live in CI

How to Search a PyPI Username with WhatsMyName App

No account, no install, no cost. Results in under 90 seconds.

Step 1

Go to WhatsMyName App

Open whatsmynameapp.us in any browser. No account needed.

Step 2

Enter the maintainer handle

Copy the handle from the maintainer section of the PyPI project page rather than inferring it from the package name.

Step 3

Run the search

Click Search. WhatsMyName App checks all 732 platforms in parallel, including PyPI.

Step 4

Find the PyPI result

Results stream in as each check completes. Look for the PyPI entry showing confirmed or not found.

Step 5

Click through to verify

Open a confirmed result to see which projects the account maintains and how long it has been publishing.

Step 6

Cross-check the registries

Review GitHub, npm and Docker Hub in the same scan. A maintainer who publishes across registries under one handle has a much more verifiable identity.

Step 7

Export the results

When the scan finishes, export every found account to CSV to attach to a dependency review.

What WhatsMyName App Shows for PyPI

A confirmed PyPI result links to the maintainer profile and the projects it publishes. For review purposes the signals that matter are how long the account has existed, how many projects it maintains, and whether those projects have plausible release histories rather than a single recent upload.

A not-found result against a handle you copied from a project page normally means a typo. A handle that resolves on PyPI but appears nowhere else in the scan is the pattern worth slowing down for, because a publisher with no verifiable presence anywhere is exactly what a throwaway or typosquatting account looks like.

Ready to check a PyPI username?

Open WhatsMyName App

After Finding a PyPI Account

For a dependency review, check that the PyPI handle, the GitHub account under the same handle, and the repository link on the project page all agree. Then look at how the project publishes: releases pushed from CI with long lived tokens are the specific weakness the 2026 attacks exploited.

Also weigh timing. A long standing package that suddenly changes maintainers, publishes outside its usual cadence, or ships a release with no corresponding repository commit is worth pausing on. In the litellm case the malicious versions were live for under an hour, which is why review at install time matters more than review at adoption time.

If you maintain packages, your handle footprint is your phishing surface. Attackers enumerate where a maintainer exists before targeting them, and 2026 saw multiple campaigns that captured multi factor codes through real time proxies. Knowing which platforms carry your handle tells you where to expect the attempt.

  • Match PyPI handle, GitHub account and repository link
  • Check whether releases come from CI tokens
  • Watch for maintainer or cadence changes on established packages
  • Maintainers: enumerate your own footprint before an attacker does

Related Platform Searches

WhatsMyName App checks these platforms alongside PyPI in a single search. Explore the guides below or browse all OSINT tools available on this site.

Find Any GitHub Username with WhatsMyName App

Most Python projects are developed and released from GitHub, so a matching account with real commit history is the core provenance check.

Find Any npm Username with WhatsMyName App

The JavaScript registry saw the same style of maintainer compromises in 2026, and many developers publish to both under one handle.

Find Any Docker Hub Username with WhatsMyName App

Python tooling often ships as container images too, so checking Docker Hub completes the picture of what a handle distributes.

Every platform guide on this site is listed on the WhatsMyName App guide.

Frequently Asked Questions about PyPI Username Search

How do I check who maintains a Python package?

Copy the handle from the maintainer section of the PyPI project page, then search it in WhatsMyName App. The PyPI result confirms the profile exists and the rest of the scan shows where else the handle appears.

Why does PyPI maintainer identity matter?

Because it is the attack path. In March 2026 malicious litellm releases were published after an attacker obtained publishing credentials, and were downloaded over 119,000 times in roughly forty minutes before being quarantined.

Does a familiar package name mean a trusted publisher?

No. Project names and maintainer handles are unrelated, and anyone can publish a package with a plausible name. That mismatch is exactly how typosquatting works.

What if the handle exists on PyPI but nowhere else?

Treat it as a caution signal rather than proof of anything. A publisher with no GitHub or other presence has no history you can verify, which is the shape of a throwaway account.

How was the litellm attack carried out?

The attacker exfiltrated a publish token from a GitHub Actions runner and used it to push two malicious versions. The payload ran on every Python process start and stole SSH keys and cloud credentials.

Is checking a PyPI handle legal?

Yes. All of it is public index data that PyPI publishes for exactly this purpose. See whether WhatsMyName App is safe to use for the wider context.

I maintain a PyPI project, what should I do with this?

Search your own handle and see where it appears. That list is what an attacker enumerates before phishing you, and it also tells you which accounts need the strongest protection.

Search Any PyPI Username Now

WhatsMyName App checks PyPI and 731 other platforms simultaneously. Free, no sign-up, results in under 90 seconds. Read the full WhatsMyName App guide to get the most out of every search.

Run a PyPI Username Search