ended5월 2일· 1 sources
Shai-Hulud 테마 악성코드가 PyTorch Lightning AI 학습 라이브러리에서 발견됨 | Semgrep
Why it matters
This attack marks a sophisticated evolution in supply chain threats by demonstrating cross-platform worm propagation from PyPI to npm. It specifically targets AI developers by weaponizing popular tools like Claude Code and VS Code, highlighting the increasing automation of data exfiltration and persistence in modern cyberattacks.
1
Sources
+0
24h
—
Growth
142d
Active
PyTorch Lightningsupply chain attackPyPInpmShai-HuludClaude Code