#8
BleepingComputer
general
May 04, 2026 at 17:15 UTC
Backdoored PyTorch Lightning package drops credential stealer
By Bill Toulas
AI Summary
A malicious version of the PyTorch Lightning package on the Python Package Index (PyPI) delivers credential-stealing malware targeting browsers, environment files, and cloud services. This supply chain attack demonstrates the ongoing threat to open-source package repositories used by machine learning developers.
Relevance score: 78.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →