ended5월 1일· 1 sources

PyTorch Lightning Supply Chain Attack Spreads Across PyPI and npm Ecosystems

PyTorch Lightning 공급망 공격으로 개발자 자격증명 탈취, npm까지 연쇄 확산

Why it matters

PyTorch Lightning, a critical deep learning framework used across AI development, was compromised in versions 2.6.2 and 2.6.3 through a supply chain attack that automatically executes malware on installation. The attack steals developer credentials and cloud secrets while leveraging npm publish permissions to propagate across the JavaScript ecosystem—a sophisticated cross-ecosystem threat that endangers developers across multiple platforms.

1
Sources
+0
24h
Growth
140d
Active
PyTorch Lightningsupply chain attackcredential theftnpm propagationJavaScript

Sources

Related Issues