Malicious PyTorch Lightning update hits AI supply chain security
ID: d0133cba-82d8-5733-b79c-12681a0b0d06
STIX ID: report--d0133cba-82d8-5733-b79c-12681a0b0d06
Feed Name: Security Affairs
A malicious PyTorch Lightning release (v2.6.3) was briefly published to PyPI and, when imported, launched a background process that downloaded a JavaScript runtime and executed an 11.4 MB obfuscated payload (ShaiWorm) to steal .env files, API keys, browser-stored credentials, and cloud provider keys and to allow remote command execution; the package was removed, users were urged to rotate credentials, Microsoft detected and blocked the threat, and Lightning AI is investigating the supply-chain compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
