Over 10 years we help companies reach their financial and branding goals. Engitech is a values-driven technology agency dedicated.

Gallery

Contacts

411 University St, Seattle, USA

engitech@oceanthemes.net

+1 -800-456-478-23

A threat actor cluster has simultaneously poisoned packages across three major software ecosystems – PyPI, npm, and Packagist – embedding credential-stealing, self-propagating malware into PyTorch Lightning (versions 2.6.2 and 2.6.3), the Intercom npm client (version 7.0.4), and the Intercom PHP library (version 5.0.2). Any organization whose developers or CI/CD pipelines installed these versions is at risk of having cloud credentials, API keys, and pipeline secrets exfiltrated. Given PyTorch Lightning’s presence in AI/ML workflows and Intercom’s enterprise customer communication footprint, the potential blast radius spans both production AI infrastructure and customer-facing platforms.

Author

Tech Jacks Solutions