Hackers target Python devs in phishing attacks using fake PyPI site
bleepingcomputer.com
bleepingcomputer.com
It has nothing to do with "knowing Python well". It's a standard web-based phishing attack. If you publish packages on PyPI, then you will commonly also use the pypi.org web interface to manage a user and/or organization account. The attack isn't trying to exploit any kind of ignorance of what PyPI is or how Python works, or how the Python packaging ecosystem works. It's trying to exploit the visual confusion between "i" and "j".
Related: