Jan. 4, 2023, 5 p.m. | Cedric Pernet

Security on TechRepublic www.techrepublic.com

A nightly build version of a machine-learning framework dependency has been compromised. The package ran malicious code on affected systems and stole data from unsuspecting users.


The post Machine-Learning Python package compromised in supply chain attack appeared first on TechRepublic.

attack build code compromised data data theft dependency developer framework linux foundation machine machine learning malicious nightly package package compromise pypi python python package pytorch security supply supply chain supply chain attack systems version

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Security Compliance Strategist

@ Grab | Petaling Jaya, Malaysia

Cloud Security Architect, Lead

@ Booz Allen Hamilton | USA, VA, McLean (1500 Tysons McLean Dr)