PyTorch Lightning hit by network compromise
Incident
Summary
Hide ▲
Show ▼
A malicious PyTorch Lightning release on PyPI created a supply-chain compromise that can steal credentials as soon as the package is imported. The backdoored version 2.6.3 uses a hidden execution chain to download Bun v1.3.13 and run an obfuscated payload. That payload targets .env files, browser-stored secrets, and AWS, Azure, and GCP credentials, putting developer and cloud accounts at risk. Microsoft Threat Intelligence says Defender detected and blocked the activity on a small number of devices, and the package was reverted to 2.6.1.
Related Happenings
BoryptGrab infostealer variant delivered via fake GitHub repositories
Malware Activity
H score30
First: 14.07.2026 22:15
Last: 14.07.2026 22:15
Sources 1
About this happening:
A BoryptGrab infostealer variant is being delivered through fake GitHub repositories, expanding a credential-theft operation that can drain browser, wallet, and messaging...
BoryptGrab infostealer variant delivered via fake GitHub repositories
Malware ActivityAbout this happening: A BoryptGrab infostealer variant is being delivered through fake GitHub repositories, expanding a credential-theft operation that can drain browser, wallet, and messaging...
Jscrambler 8.14.0 malicious preinstall infostealer release
Malware Activity
H score9
First: 11.07.2026 20:59
Last: 11.07.2026 20:59
Sources 1
About this happening:
The jscrambler 8.14.0 npm release now ships a malicious preinstall hook that runs a Rust infostealer during install, putting developer and CI secrets at risk on ...
Jscrambler 8.14.0 malicious preinstall infostealer release
Malware ActivityAbout this happening: The jscrambler 8.14.0 npm release now ships a malicious preinstall hook that runs a Rust infostealer during install, putting developer and CI secrets at risk on ...
Atomic-lockfile rootkit-infostealer distribution through AUR packages
Malware Activity
H score3
First: 12.06.2026 20:03
Last: 12.06.2026 20:03
Sources 1
About this happening:
AUR packages are distributing the atomic-lockfile Linux rootkit and infostealer through compromised build scripts, with more than 400 packages reported and the o...
Atomic-lockfile rootkit-infostealer distribution through AUR packages
Malware ActivityAbout this happening: AUR packages are distributing the atomic-lockfile Linux rootkit and infostealer through compromised build scripts, with more than 400 packages reported and the o...
Shai-Hulud worm clone activity on NPM
Malware Activity
H score69
First: 18.05.2026 12:45
Last: 18.05.2026 12:45
Sources 1
About this happening:
The Shai-Hulud malware activity has continued to evolve across the npm supply chain and related developer ecosystems. It first infected npm packages in September 202...
Shai-Hulud worm clone activity on NPM
Malware ActivityAbout this happening: The Shai-Hulud malware activity has continued to evolve across the npm supply chain and related developer ecosystems. It first infected npm packages in September 202...
Node-ipc malicious versions with stealer/backdoor payload
Malware Activity
H score34
First: 14.05.2026 20:22
Last: 14.05.2026 20:22
Sources 1
About this happening:
Three node-ipc releases now carry an obfuscated stealer/backdoor that can harvest developer and cloud secrets from any system that loads the package. The malicious cod...
Node-ipc malicious versions with stealer/backdoor payload
Malware ActivityAbout this happening: Three node-ipc releases now carry an obfuscated stealer/backdoor that can harvest developer and cloud secrets from any system that loads the package. The malicious cod...
Timeline
-
04.05.2026 20:15 2 articles · 2mo ago
Lightning AI discloses malicious PyTorch Lightning 2.6.3
Initial DisclosureLightning AI discloses that PyTorch Lightning 2.6.3 on PyPI contains a hidden execution chain that triggers on import, downloads a JavaScript runtime, and runs an obfuscated payload tied to credential theft from browsers, .env files, and cloud services.
Show sources
- Backdoored PyTorch Lightning package drops credential stealer — www.bleepingcomputer.com — 04.05.2026 20:15
- Backdoored PyTorch Lightning package drops credential stealer — www.bleepingcomputer.com — 04.05.2026 20:15
-
04.05.2026 20:15 1 articles · 2mo ago
Microsoft Defender detects and blocks ShaiWorm on customer devices
Detection Ioc UpdateMicrosoft Threat Intelligence reports that Defender detected and prevented the malicious PyTorch Lightning routine in customer environments, notified the maintainer, and observed activity affecting a small number of devices in a narrow set of environments.
Show sources
- Backdoored PyTorch Lightning package drops credential stealer — www.bleepingcomputer.com — 04.05.2026 20:15
-
04.05.2026 20:15 1 articles · 2mo ago
PyTorch Lightning reverts package to 2.6.1 on PyPI
Mitigation Patch UpdatePyTorch Lightning has been reverted to 2.6.1 on PyPI, which is described as safe to use, while users who imported 2.6.3 are advised to rotate all secrets, keys, and tokens that may have been exposed.
Show sources
- Backdoored PyTorch Lightning package drops credential stealer — www.bleepingcomputer.com — 04.05.2026 20:15