PyTorch dependency poisoned with malicious code

An unknown attacker used the PyPI code repository to get developers to download a compromised PyTorch dependency that included malicious code designed to steal system data. Developers who last week downloaded the nightly builds of the open source PyTorch framework also unknowingly installed a malicious version of the dependency found in the Python Package Index, according to PyTorch’s maintainers.

Read full article on The Register

 


Date:

Categorie(s):

Tag(s):