Malicious PyTorch Lightning update hits AI supply chain security
Source: Security Affairs · Category: Supply Chain
Malicious PyTorch Lightning update (v2.6.3) on PyPI stole developer credentials before removal. Law firms using Python-based AI development, machine learning tools, or hiring engineers who work with PyTorch face supply-chain credential compromise risk. Audit internal AI/ML tooling immediately.