CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Malicious PyTorch dependency 'torchtriton' on PyPI: everything you need to know

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 1759

As cited

Copy frozen at (site build).

threat intel

Malicious PyTorch dependency 'torchtriton' on PyPI: everything you need to know

PyTorch developers discovered a malicious dependency confusion attack targeting the project through a fake 'torchtriton' package on PyPI. The attack aimed to compromise PyTorch users by distributing malware through a package name similar to a legitimate dependency. Security teams should verify systems for the malicious package and rotate any exposed credentials.

Why it matters: PyTorch users and organizations relying on machine learning workflows are at risk of supply chain compromise; practitioners should immediately check for the malicious package and audit access keys.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary