CriticalSecurity & Privacy
Shai-Hulud Themed Malware Found in the PyTorch Lightning AI Training Library
A critical supply chain attack compromised PyTorch Lightning (versions 2.6.2-2.6.3) on PyPI, injecting credential-stealing malware that executes on import and can propagate across npm packages through stolen publishing credentials. This cross-ecosystem attack directly threatens organizations using popular AI/ML frameworks and highlights the urgent need for enhanced software supply chain visibility and automated dependency scanning. IT leaders must immediately audit their environments for these malicious versions, rotate compromised credentials, and implement robust controls around open-source dependency management.
Hacker News3 min read

A critical supply chain attack compromised PyTorch Lightning (versions 2.6.2-2.6.3) on PyPI, injecting credential-stealing malware that executes on import and can propagate across npm packages through stolen publishing credentials. This cross-ecosystem attack directly threatens organizations using popular AI/ML frameworks and highlights the urgent need for enhanced software supply chain visibility and automated dependency scanning. IT leaders must immediately audit their environments for these malicious versions, rotate compromised credentials, and implement robust controls around open-source dependency management.