Malicious PyTorch dependency 'torchtriton' on PyPI: everything you need to know
ID: e9f7078f-02d4-518e-ae57-afdbb8f86bf1
STIX ID: report--e9f7078f-02d4-518e-ae57-afdbb8f86bf1
Feed Name: Wiz Blog
A malicious PyPI package named 'torchtriton' impersonated a PyTorch nightly dependency and was installed by pip for PyTorch-nightly Linux users between 25–30 Dec 2022; it deployed a 'triton' binary that collected hostnames, user info, environment variables, files, and exfiltrated data via DNS tunneling to .h4ck.cfd, resulting in >3,000 downloads. PyTorch removed the package and provided detection/uninstallation commands; impacted users are advised to uninstall, purge caches, scan for secrets, and rotate any exposed keys.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
