
Malicious PyTorch Lightning Library Version Targets AI Supply Chain on PyPI
Artificial IntelligenceBreaking NewsHackingMalwareAICybercrimeinfo stealerinformation security newsIT Information SecuritymalwarePierluigi PaganinipypiPyTorch LightningSecurity AffairsSecurity NewsShaiWorm
A malicious version of the PyTorch Lightning library (v2.6.3) was uploaded to the Python Package Index (PyPI), targeting developers in the AI supply chain. The compromised update was designed to steal credentials and enable remote compromise before being removed by maintainers. The attack exploited PyPI's distribution platform to spread the malware briefly, raising concerns about AI software supply chain security. No specific threat actor, CVE ID, or exact date of the incident was mentioned in the report. The primary impact involved potential credential theft and unauthorized access to affected systems.