Malicious PyTorch Lightning update hits AI supply chain security


Malicious PyTorch Lightning update hits AI supply chain security

Pierluigi Paganini
May 06, 2026

A malicious PyTorch Lightning update (v2.6.3) on PyPI spread briefly, stealing credentials and raising major concerns about AI supply chain security.

A malicious update of the PyTorch Lightning library exposed developers to credential theft and remote compromise. Attackers uploaded version 2.6.3 to the Python Package Index (PyPI), where it spread among developers before maintainers removed it at the end of April.

PyTorch Lightning is an open-source framework built on top of PyTorch that simplifies how developers train and deploy deep learning models.

Given the library’s popularity in AI development, the incident raised serious concerns about the security of software supply chains.

The compromised package executed hidden code as soon as developers imported it. It launched a background process, downloaded a JavaScript runtime (Bun), and ran a large, heavily obfuscated payload. Microsoft identified the malware as ShaiWorm, a credential stealer designed to extract sensitive information from infected systems.

lightning==2.6.3 (published on PyPI as py3-none-any wheel) contains a hidden execution chain that silently downloads a JavaScript runtime (Bun) and executes an 11.4 MB heavily obfuscated JavaScript payload upon import lightning. This payload contains credential-stealing functionality targeting cloud providers, browsers, and environment files.” reads the advisory.

The malware targeted a wide range of data. It searched for .env files, API keys, GitHub tokens, and credentials stored in browsers like Chrome, Firefox, and Brave. It also collected access keys for major cloud platforms, including AWS, Azure, and Google Cloud. Beyond data theft, the malware allowed attackers to execute arbitrary commands on the system, effectively giving them full control over compromised environments.

Lightning AI quickly warned users about the risk. The company advised anyone who used version 2.6.3 to rotate all credentials and secrets immediately. It removed the malicious release and replaced it with a safe version. At the same time, Microsoft Defender detected and blocked the threat on affected endpoints, limiting its spread to a relatively small number of systems.

It is still unclear how attackers managed to insert the backdoor. Lightning AI continues to examine whether a compromised developer account, build system, or third-party dependency enabled the attack. The company also audits other recent releases to ensure no additional malicious code remains.

“Observed activity remains limited to a small number of devices and appear contained to a narrow set of environments.” states Microsoft. “We are also investigating container-based telemetry and registry-related signals that may indicate potential compromise in some scenarios.”

This incident shows how attackers increasingly target trusted components in the AI and Python ecosystems. Widely used libraries offer an efficient entry point, allowing attackers to reach many developers at once. It highlights the need for stronger safeguards, including dependency verification, runtime monitoring, and stricter controls around software distribution and updates.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, PyTorch Lightning)







Source link

Leave a Reply

Subscribe to Our Newsletter

Get our latest articles delivered straight to your inbox. No spam, we promise.

Recent Reviews


Disney+ is embracing the Dark Side, as Star Wars: Maul – Shadow Lord is about to emerge on the service. Before The Mandalorian brought Star Wars into live-action television, the franchise was thriving in animated form, thanks to the initial success of Star Wars: The Clone Wars. Among the many new twists that the series introduced, one of the most notable developments was the return of Darth Maul after his apparent death in Star Wars: The Phantom Menace.

Now, after several series that have developed the character from a terrifying figure to a tragic Sisyphean antagonist, Maul – Shadow Lord will throw the character into a fight against the tyranny of the Empire, leading to tense chases and surprise alliances:

What is Star Wars: Maul – Shadow Lord?

The former Sith Lord returns

Star Wars: Maul – Shadow Lord is set on the newly introduced world of Janix, a planet on the Mid Rim of the galaxy far, far away that has been unbothered by the still young Galactic Empire in the wake of the Clone Wars. While the planet’s Tactical Defense Force keeps the population in check, the planet has become host to individuals looking to avoid Imperial interests, either out of fear for their lives or to rebuild in the shadows.

Following his usurping of Mandalore and escape from Republic custody in The Clone Wars season 7, Maul is attempting to rebuild the Shadow Collective crime syndicate with what remains of his forces, including fellow Dathomirian Zabraks and Mandalorian supercommandos. As Maul’s operations become too much for the TDF to handle, the Empire establishes a foothold on Janix. While grappling with Stormtroopers and Inquisitors, Maul must make an uneasy alliance with a young Jedi on the run if he wants to initiate his plan for revenge.

Who is in Star Wars: Maul – Shadow Lord?

An Oscar nominee joins the cast

Star Wars: Maul – Shadow Lord sees Sam Witwer reprise the role of the former Sith Lord-turned-crime lord from his appearances across Star Wars: The Clone Wars and Star Wars: Rebels. Fellow Rebels stars Vanessa Marshall and Steve Blum join him as the Mandalorian Rook Kast and Zabrak fighter Icarus. Meanwhile, Gideon Adlon takes on the role of the young Twilek Padawan Devon Izara, while Dennis Haysbert’s Master Eeko-Dio Daki hopes to guide her in the Dark Times.

Meanwhile, Oscar-nominee Wagner Moura will provide the voice of TDF captain Brander Lawson, with Richard Ayoade voicing his partner Two-Boots, and Charlie Bushnell voicing his son, Rylee. Chris Diamantopoulos and Stephen Stanton will voice crime lords Looti Vario and Marg Krim, David W. Collins will voice Spybot, and A.J. LoCascio will voice Marrok, the Inquisitor first introduced in Ahsoka.

Subscription with ads

Yes, the Disney Basic plan

Simultaneous streams

Up to 4


When does Star Wars: Maul – Shadow Lord take place?

Stuck between two familiar events

Devon is imprisoned in in Star Wars_ Maul - Shadow Lord. Credit: Lucasfilm

Star Wars: Maul – Shadow Lord is set during the Dark Times, the period of the Star Wars franchise between Revenge of the Sith and A New Hope where the Empire was expanding its power over the galaxy, with those who opposed them choosing to lurk in the shadow. This period has been explored in The Bad Batch, Star Wars Rebels, Obi-Wan Kenobi, Andor, and the Star Wars: Jedi video game franchise, as well as briefly explored in select episodes of the Tales of the Jedi, Tales of the Empire, and Tales of the Underworld anthology series.

Some TV show characters with the Andor logo in the background.


Finished Andor? Stream These Star Wars Shows and Movies Next

The Star Wars universe has plenty to watch to keep the Force flowing now that Andor’s finished.

In the trailer itself, Maul and Devon are seen facing Stormtroopers wearing TK armor, an early version of Stormtrooper armor that was introduced in The Bad Batch season 1. This means that the Empire is still in a time of transition from the Galactic Republic to the forces that we see closer to the Star Wars Original Trilogy. As such, Maul – Shadow Lord events are likely happening concurrently with the events of The Bad Batch’s later two seasons.

Maul – Shadow Lord can finally explain the final years of the Sith Lord’s life

Time to explore new horizons

Maul ignites half of his lightsaber in in Star Wars_ Maul - Shadow Lord. Credit: Lucasfilm

While The Clone Wars successfully resurrected Maul and Rebels would give him a fitting end, there is still a large portion of his story left unexplored. While it is unclear whether the series will receive multiple seasons, the show will explore how he rearranged his forces from the Shadow Collective into Crimson Dawn, the faction first introduced in Solo: A Star Wars Story. Paul Bettany’s Dryden Vos did feature as a cameo in The Clone Wars’s final season, but the arc largely focused on Maul’s Mandalorian forces over his other agents. As such, Maul – Shadow Lord can complete his turn from a man well-aware of Smith’s schemes into his own fully-fledged criminal mastermind.

Furthermore, the presence of Devon in Maul’s story is allowing Lucasfilm to dust off long-scrapped plans. Prior to the Disney acquisition, a Darth Maul-focused game was in development that saw Maul paired with Darth Talon, another red-skinned Twilek, at the behest of George Lucas himself, as the pair took on the galaxy. While Devon may not be a direct adaptation of Talon in the existing canon, Witwer has teased that the series will finally adapt several unused concepts for Maul to screen, and Devon’s visual similarities to Talon could suggest that the series will fulfill one of Lucas’s final ideas for the franchise.

When will Star Wars: Maul – Shadow Lord stream?

Two-episode premiere coming soon

Maul in hiding in in Star Wars_ Maul - Shadow Lord. Credit: Lucasfilm

Star Wars: Maul – Shadow Lord will arrive on Disney+ on April 6th with a two-episode premiere. The series will then release two new episodes every Monday, culminating in the finale on May 4. While one of the shorter Star Wars series, Maul’s long-awaited 10-part story will finally give fans a glimpse into the mind of one of the Dark Side’s most terrifying warriors.



Source link