Backdoored PyTorch Lightning package drops credential stealer
ID: cf379353-3feb-5fdf-85eb-67bf3c2acf61
STIX ID: report--cf379353-3feb-5fdf-85eb-67bf3c2acf61
Feed Name: Bleeping Computer
A malicious PyTorch Lightning package (v2.6.3) on PyPI executed a hidden chain that downloaded Bun and ran an obfuscated 11.4 MB JavaScript payload ("router_runtime.js", detected as "ShaiWorm") upon import. The payload targets .env files, API keys, browser data (Chrome/Firefox/Brave), and cloud credentials (AWS/Azure/GCP) and can execute arbitrary commands; Microsoft Defender detected and limited observed impact, the package was reverted to 2.6.1, and affected users are advised to rotate secrets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
