Gallery

Contacts

411 University St, Seattle, USA

engitech@oceanthemes.net

+1 -800-456-478-23

A malicious version of PyTorch Lightning (v2.6.3) was published to PyPI and silently stole cloud and browser credentials on import. With approximately 11 million monthly downloads, the package is widely embedded in AI/ML development pipelines across industries. Any organization where developers installed this version may have exposed AWS, Azure, GCP credentials and browser-stored secrets, creating direct risk of cloud account takeover and data exfiltration.

Author

Tech Jacks Solutions