logo

Malicious PyTorch Lightning update hits AI supply chain security

ID: d0133cba-82d8-5733-b79c-12681a0b0d06

STIX ID: report--d0133cba-82d8-5733-b79c-12681a0b0d06

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2026-05-06

Date Updated: 2026-05-06

Author: Pierluigi Paganini

...
...

A malicious PyTorch Lightning release (v2.6.3) was briefly published to PyPI and, when imported, launched a background process that downloaded a JavaScript runtime and executed an 11.4 MB obfuscated payload (ShaiWorm) to steal .env files, API keys, browser-stored credentials, and cloud provider keys and to allow remote command execution; the package was removed, users were urged to rotate credentials, Microsoft detected and blocked the threat, and Lightning AI is investigating the supply-chain compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.