As cited
Copy frozen at (site build).
threat intel
Malicious PyTorch dependency 'torchtriton' on PyPI: everything you need to know
PyTorch developers discovered a malicious dependency confusion attack targeting the project through a fake 'torchtriton' package on PyPI. The attack aimed to compromise PyTorch users by distributing malware through a package name similar to a legitimate dependency. Security teams should verify systems for the malicious package and rotate any exposed credentials.
Why it matters: PyTorch users and organizations relying on machine learning workflows are at risk of supply chain compromise; practitioners should immediately check for the malicious package and audit access keys.
- Source published
- First seen by Cybersecurity Tracker