In-depth Analysis of the PyTorch Dependency Confusion
ID: c4651ca3-0af6-5e52-856b-7cd8e021af16
STIX ID: report--c4651ca3-0af6-5e52-856b-7cd8e021af16
Feed Name: Aqua Security Blog
**Executive Summary:** Between Dec 25–30, 2022 a dependency confusion supply-chain attack compromised the PyTorch-nightly dependency chain by uploading a malicious 'torchtriton' package to PyPI; the package contained an inserted binary (MD5 908596ffe11c30d1669431f3f4cb54f2) launched from __init__.py that collected sensitive files and system data and exfiltrated it via DNS to h4ck.cfd (using DNS server wheezy.io). The report includes static and dynamic malware analysis, decrypted traffic examples, mapped MITRE ATT&CK techniques, IOCs, and both immediate and general mitigation recommendations (uninstall affected packages, purge pip cache, use SBOM/dependency scanning and runtime protections).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
