Shai-Hulud Malware Found in PyTorch Lightning Library (semgrep.dev)
- Discovery of malicious code within AI training library dependencies.
- The attack vector targets environment variables and credentials.
- Highlights systemic risks in open-source AI infrastructure.
"Security researchers have uncovered a malicious dependency in the PyTorch Lightning AI training library, dubbed 'Shai-Hulud'. The compromise allows attackers to scrape sensitive environment variables and API credentials during the execution of machine learning training workloads. This attack highlights a critical vulnerability in the open-source supply chain for AI development, where automated library updates can bypass security filters. Organizations relying on PyTorch Lightning for large-scale AI research must conduct immediate audits of their dependencies and rotate all credentials previously used within these training environments to prevent unauthorized access."
no comments yet.