News

Malicious PyTorch Lightning update hits AI supply chain security

  • Pierluigi Paganini--Securityaffairs.com
  • published date: 2026-05-06 07:04:22 UTC

A malicious PyTorch Lightning update (v2.6.3) on PyPI spread briefly, stealing credentials and raising major concerns about AI supply chain security. A malicious update of the PyTorch Lightning library exposed developers to credential theft and remote comprom…

Malicious PyTorch Lightning update hits AI supply chain security A malicious update of the PyTorch Lightning library exposed developers to credential theft and remote compromise. Attackers uploaded … [+3330 chars]