logo

PyTorch Lightning and Intercom-client Hit in Supply Chain Attacks to Steal Credentials

ID: 2c019c83-edbc-5dfd-a282-acb6e7750f96

STIX ID: report--2c019c83-edbc-5dfd-a282-acb6e7750f96

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2026-04-30

Date Updated: 2026-04-30

Author: [email protected] (The Hacker News)

...
...

A supply-chain attack distributed malicious PyTorch Lightning releases (v2.6.2 and v2.6.3) that auto-execute on import and download a Bun runtime to run an obfuscated JS payload aimed at credential harvesting. Harvested GitHub tokens are validated and used to inject worm-like commits into writable repositories, while an npm-based propagation modifies local packages to spread the compromise; the activity is attributed to TeamPCP and is linked to the broader Mini Shai-Hulud campaign. Mitigation guidance includes blocking and removing the affected package versions, downgrading to 2.6.1, and rotating exposed credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.