Shai-Hulud Themed Malware Found in the PyTorch Lightning AI Training Library
PyTorch Lightning, trusted by thousands of AI teams, just got compromised. Here's what got infected.

Why it matters
A malware-laced dependency in one of the most widely used AI training libraries exposes a critical supply-chain vulnerability in the open-source AI stack. This affects any team building models with PyTorch Lightning and highlights governance gaps in AI infrastructure security.
The key facts
6 to knowMalware discovered in PyTorch Lightning dependency chain
Shai-Hulud themed naming suggests deliberate obfuscation
Published April 30, 2026 on Semgrep security blog
317 HN points, 104 comments indicate significant developer concern
PyTorch Lightning is widely adopted for AI/ML training workflows
Supply-chain attack vector targeting AI infrastructure
Go to the source
Hacker Newssemgrep.dev
Publisher excerpt: Article URL: Comments URL: Points: 317 # Comments: 104