Backdoored PyTorch Lightning Package Steals Cloud Credentials from AI Developers
A malicious version of PyTorch Lightning (v2.6.3) was published to PyPI, embedding a hidden execution chain that silently downloads a JavaScript runtime and executes a heavily obfuscated …