ended5월 1일· 1 sources
PyTorch Lightning Supply Chain Attack Spreads Across PyPI and npm Ecosystems
PyTorch Lightning 공급망 공격으로 개발자 자격증명 탈취, npm까지 연쇄 확산
Why it matters
PyTorch Lightning, a critical deep learning framework used across AI development, was compromised in versions 2.6.2 and 2.6.3 through a supply chain attack that automatically executes malware on installation. The attack steals developer credentials and cloud secrets while leveraging npm publish permissions to propagate across the JavaScript ecosystem—a sophisticated cross-ecosystem threat that endangers developers across multiple platforms.
1
Sources
+0
24h
—
Growth
140d
Active
PyTorch Lightningsupply chain attackcredential theftnpm propagationJavaScript