Developers and admin around the world use and trust public repositories, such as Python's PyPi, to provide secure means to download, install, and manage 3rd part libraries and tools. But is this trust misplaced? This talk will cover how PyPi can be abused to leak personal information, and provide malware C2 and exfiltration channels. This talk will also cover how to help the open source community and ourselves improve the balance between usability and security.