PyTorch Lightning and Intercom-client Hit in Supply Chain Attacks to Steal Credentials
2026-05-01T01:24:13Z•74db4772a29081473eb92bc972dba349c7f1a089bb9a243b5560526eb87b0427
active-exploitationbackdoorcisa-kevcredential-theftgithublocal-privilege-escalationmalicious-packagesnpmpyPIpythonransomwarercesql-injectionsupply-chain-attack
What happened
Multiple high-impact security incidents were reported: a PyPI supply-chain compromise pushing malicious PyTorch Lightning releases (2.6.2/2.6.3) and other credential‑stealing package campaigns (including SAP-related npm packages and Intercom-client), widespread active exploitation of critical/ high-severity vulnerabilities (LiteLLM CVE-2026-42208 SQLi, GitHub CVE-2026-3854 RCE, Hugging Face LeRobot CVE-2026-25874 unauthenticated RCE, Linux local LPE CVE-2026-31431, Microsoft Windows/ConnectWise issues added to CISA KEV and CVE-2026-32202 active exploitation), and several malware/backdoor/ransw
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 74db4772a29081473eb92bc972dba349c7f1a089bb9a243b5560526eb87b0427
- Enrichment time
- 2026-05-01T01:24:13Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.