Jan. 4, 2023, 5 p.m. | MalBot

Malware Analysis, News and Indicators - Latest topics malware.news


A classic dependency confusion attack revealed itself last week. The PyTorch open source software supply chain was compromised by a hacker publishing a malicious torchtriton clone on PyPI.


The perp was pretending to be an ethical researcher. However, the alarm was raised by their efforts to obfuscate the malware and exfiltrate sensitive data. Not only that, but the stolen data could have been viewed in transit.


It’s proof, once again, that DevOps needs to get serious about mitigation. In …

alarm attack compromised data dependency dependency confusion devops hacker malicious malware open source open source software supply open source software supply chain publishing pypi pytorch researcher sensitive data software software supply chain stolen supply supply chain supply chain attack

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Security Compliance Strategist

@ Grab | Petaling Jaya, Malaysia

Cloud Security Architect, Lead

@ Booz Allen Hamilton | USA, VA, McLean (1500 Tysons McLean Dr)