malware pypi

pytorch-lightning

discovered 2026-04-30

pytorch-lightning is identified in the SafeDep analysis "PyTorch Lightning Compromised: Shai-Hulud Worm Reaches PyPI". PyPI yanked PyTorch Lightning versions 2.6.2 and 2.6.3 after both embedded a two-stage credential-stealing payload. Any import of the library spawns an 11MB obfuscated JavaScript worm identical to the Shai-Hulud payload seen in the April 29 SAP npm campaign.

Threat types

credential_stealer data_exfiltration worm

Malicious versions

  • 2.5.3

Campaigns

Indicators

Techniques

Read the full analysis →