Post #2742644
2026-04-30 18:09 UTC
The Shai-Hulud campaign just escalated from npm to PyPI.
PyTorch Lightning (pip install lightning) was compromised with the same Dune-themed malware. Entry point is Python, but the worm propagates through npm.
Your ML training environment now infects your JavaScript packages. The ecosystem boundary just dissolved.
Semgrep has the full breakdown. 107 points on HN.
#infosec #malware #python #supplychain
Replies (0)
No replies.