Tag: package exploitation
2 articles

Malware Worm Exploits Tensorlake npm Package to Steal Credentials
A malware worm has been discovered exploiting the popular Tensorlake npm package to steal sensitive credentials, with the first malicious commit occurring on October 7, 2026, at 01:20 a.m. UTC. The compromised package, version 0.5.144, was quickly taken down after publishing to the npm registry on October 8, 2026.

Malicious PyTorch Lightning Package Exploits Supply Chain to Steal Credentials
A malicious version of the popular PyTorch Lightning package, downloaded over 11 million times, was found to contain a stealthy backdoor that steals credentials by silently executing a heavily obfuscated JavaScript payload. The compromised package, version 2.6.3, triggers the malicious routine automatically when imported, putting users at risk.