logo

Backdoored PyTorch Lightning package drops credential stealer

ID: cf379353-3feb-5fdf-85eb-67bf3c2acf61

STIX ID: report--cf379353-3feb-5fdf-85eb-67bf3c2acf61

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2026-05-04

Date Updated: 2026-05-05

Author: Bill Toulas

...
...

A malicious PyTorch Lightning package (v2.6.3) on PyPI executed a hidden chain that downloaded Bun and ran an obfuscated 11.4 MB JavaScript payload ("router_runtime.js", detected as "ShaiWorm") upon import. The payload targets .env files, API keys, browser data (Chrome/Firefox/Brave), and cloud credentials (AWS/Azure/GCP) and can execute arbitrary commands; Microsoft Defender detected and limited observed impact, the package was reverted to 2.6.1, and affected users are advised to rotate secrets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.