Skip to main content

Tag: package exploitation

2 articles

Brightly-lit coding workspace with laptop and development tools, subtle network infrastructure in background.

Malware Worm Exploits Tensorlake npm Package to Steal Credentials

A malware worm has been discovered exploiting the popular Tensorlake npm package to steal sensitive credentials, with the first malicious commit occurring on October 7, 2026, at 01:20 a.m. UTC. The compromised package, version 0.5.144, was quickly taken down after publishing to the npm registry on October 8, 2026.

Analyst 207
Laptop workstation with PyTorch Lightning package terminal open, displaying code on a neutral background.

Malicious PyTorch Lightning Package Exploits Supply Chain to Steal Credentials

A malicious version of the popular PyTorch Lightning package, downloaded over 11 million times, was found to contain a stealthy backdoor that steals credentials by silently executing a heavily obfuscated JavaScript payload. The compromised package, version 2.6.3, triggers the malicious routine automatically when imported, putting users at risk.

Analyst 207