PulseAugur
实时 04:52:37
English(EN) Shai-Hulud Themed Malware Found in the PyTorch Lightning AI Training Library https:// semgrep.dev/blog/2026/maliciou s-dependency-in-pytorch-lightning-used-for-

Shai-Hulud 恶意软件感染 PyTorch Lightning AI 训练库

供应链攻击已导致 PyTorch Lightning AI 训练库(版本 2.6.2 和 2.6.3)受到损害。该恶意代码以《沙丘》中的“Shai-Hulud”为主题,导入后会自动执行,窃取凭证、身份验证令牌和云密钥。此次攻击还试图污染 GitHub 存储库,并通过将恶意代码注入其他包的方式在 npm 生态系统中传播。 AI

影响 受损的 AI 开发工具可能导致大规模凭证窃取和存储库污染,影响 AI 项目的安全性。

排序理由 这是一个影响广泛使用的 AI 开发工具的安全漏洞,但它不代表新的模型发布或范式转变。

在 Mastodon — fosstodon.org 阅读 →

AI 生成摘要 · Google Gemini · 来自 6 个来源。 我们如何撰写摘要 →

Shai-Hulud 恶意软件感染 PyTorch Lightning AI 训练库

报道来源 [6]

  1. Hacker News — AI stories ≥50 points TIER_1 English(EN) · j12y ·

    PyTorch Lightning AI 训练库中发现“沙丘”主题恶意软件

  2. Mastodon — fosstodon.org TIER_1 English(EN) · [email protected] ·

    PyTorch Lightning AI 训练库中发现以沙丘魔怪为主题的恶意软件

    Shai-Hulud Themed Malware Found in the PyTorch Lightning AI Training Library https:// semgrep.dev/blog/2026/maliciou s-dependency-in-pytorch-lightning-used-for-ai-training/ # ai # malware

  3. Mastodon — fosstodon.org TIER_1 English(EN) · [email protected] ·

    新帖:PyTorch Lightning、CopyFail 和 Claude Code — 同一天发生的三个信任失败事件 Shai-Hulud 恶意软件攻击了 PyTorch Lightning。CopyFail 从未被披露

    New post: PyTorch Lightning, CopyFail, and Claude Code — Three Trust Failures on the Same Day Shai-Hulud malware hit PyTorch Lightning. CopyFail was never disclosed to distros. Claude Code allegedly scans commits for competitors. Three stories, one pattern. 15 incidents in 30 day…

  4. Mastodon — fosstodon.org TIER_1 English(EN) · [email protected] ·

    PyTorch Lightning AI 训练库中发现以沙丘魔怪为主题的恶意软件

    Shai-Hulud Themed Malware Found in the PyTorch Lightning AI Training Library https:// semgrep.dev/blog/2026/maliciou s-dependency-in-pytorch-lightning-used-for-ai-training/ # ai # malware

  5. Mastodon — mastodon.social TIER_1 English(EN) · aihaberleri ·

    📰 PyTorch Lightning 恶意软件:Shai-Hulud 攻击利用反序列化漏洞(2026) 一个伪装成 Shai-Hulud 主题依赖项的复杂恶意软件活动

    📰 PyTorch Lightning Malware: Shai-Hulud Attack Exploits Deserialization in 2026 A sophisticated malware campaign disguised as Shai-Hulud-themed dependencies has been found embedded in PyTorch Lightning’s training ecosystem, exploiting deserialization flaws to enable remote code e…

  6. Mastodon — mastodon.social TIER_1 Türkçe(TR) · aihaberleri ·

    📰 PyTorch Lightning 中的 Pickle 反序列化漏洞:2026 年的远程代码执行威胁及其解决方案 漏洞在 PyTorch Lightning 中被发现,反序列化漏洞在 PyTorch Lightning 中被发现...

    📰 PyTorch Lightning'de Pickle Deserialization Zafiyeti: 2026'da RCE Tehditleri ve Çözümü PyTorch Lightning’de keşfedilen ciddi deserializasyon zafiyetleri, kullanıcıları arbitrary kod çalıştırma saldırılarına açıyor. Shai-Hulud temalı bir zararlı yazılım senaryosu, bu zafiyetleri…