Backdoored PyTorch Lightning package drops credential stealer

Source: BleepingComputer  ·  Category: Supply Chain


Malicious PyTorch Lightning package on PyPI delivered credential stealer targeting browsers and cloud services. If firm developers or AI teams use PyTorch Lightning, compromised installations expose API keys, cloud credentials, and employee credentials. Audit Python dependencies immediately.

→ Read the full article

Read more