PyTorch Lightning and Intercom-client Hit in Supply Chain Attacks to Steal Credentials

2026-05-01T01:24:13Z74db4772a29081473eb92bc972dba349c7f1a089bb9a243b5560526eb87b0427
active-exploitationbackdoorcisa-kevcredential-theftgithublocal-privilege-escalationmalicious-packagesnpmpyPIpythonransomwarercesql-injectionsupply-chain-attack

What happened

Multiple high-impact security incidents were reported: a PyPI supply-chain compromise pushing malicious PyTorch Lightning releases (2.6.2/2.6.3) and other credential‑stealing package campaigns (including SAP-related npm packages and Intercom-client), widespread active exploitation of critical/ high-severity vulnerabilities (LiteLLM CVE-2026-42208 SQLi, GitHub CVE-2026-3854 RCE, Hugging Face LeRobot CVE-2026-25874 unauthenticated RCE, Linux local LPE CVE-2026-31431, Microsoft Windows/ConnectWise issues added to CISA KEV and CVE-2026-32202 active exploitation), and several malware/backdoor/ransw

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
74db4772a29081473eb92bc972dba349c7f1a089bb9a243b5560526eb87b0427
Enrichment time
2026-05-01T01:24:13Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · PyTorch Lightning and Intercom-client Hit in Supply Chain Attacks to Steal Credentials · Baitaphish