Live Wave Icon New Blog: Why Does an npm Math Library Need an Encrypted Loader?
•
Edit Calendar Icon 18 Sep 2026
SafeDep Logo
Discover & Monitor
SCA & SBOM
SCA & SBOM

Scan dependencies, generate SBOMs, enforce policy.

AI Agent Discovery
AI Agent Discovery

See every AI tool and SDK in your org.

AI Agent Monitoring
AI Agent Monitoring

Audit every action your AI agents take.

Protect
Developer Security
Developer Security

Block malicious packages at install-time.

CI/CD Security
CI/CD Security

Block malicious packages in your pipeline.

MCP Server
MCP Server

Block threats inside your AI coding agent.

Agent API
Agent API

Threat intelligence API for custom agents.

Threat Intelligence
Threat Intelligence

Real-time malicious package verdicts.

Govern
Endpoint Protection
Endpoint Protection

Package events & AI inventory in the cloud.

Platform
Platform

Centralized policies, dashboard, compliance.

Open Source
Vet
Vet

Scan and govern your dependencies across every PR and build.

PMG
PMG

Block malicious packages at install-time, before they enter your codebase.

xbom
xbom

Generate AI-enriched BOMs using real code evidence, not just manifests.

GRYPH
GRYPH

Monitor every AI coding agent action across your projects and workflows.

Pricing How it works Blog
Documentation
SDK
API
Threat Intelligence Hub
Login Start for Free GitHub 1.5k
packages pypi
malware pypi

pytorch-lightning

discovered 2026-04-30

pytorch-lightning is identified in the SafeDep analysis "PyTorch Lightning Compromised: Shai-Hulud Worm Reaches PyPI". PyPI yanked PyTorch Lightning versions 2.6.2 and 2.6.3 after both embedded a two-stage credential-stealing payload. Any import of the library spawns an 11MB obfuscated JavaScript worm identical to the Shai-Hulud payload seen in the April 29 SAP npm campaign.

Threat types

credential_stealer data_exfiltration worm

Malicious versions

  • 2.5.3

Campaigns

  • Shai-Huludattributed-to

Indicators

  • sha256 3071422c3294e7b61cb490c57c48c8dea569bacf12e57a078293b6547d7586d3indicates
  • sha256 56070a9d8de0c0ffb1ec5c309953cf4679432df5a78df9aeb020fbb73d2be9fbindicates
  • sha256 5f5852b5f604369945118937b058e49064612ac69826e0adadca39a357dfb5b1indicates
  • sha256 d2815d425ae08cc627f1db69009442165f8bbc64b7e9157e2ff9d7aab02094d4indicates
  • sha256 8046a11187c135da6959862ff3846e99ad15462d2ec8a2f77a30ad53ebd5dcf2indicates
  • sha256 2d4e21d2e78d0868ce7894487e67c67f929d8d81d78c5b07a3ad225b13eae890indicates

Techniques

  • ttp T1195.001 Compromise Software Dependencies and Development Toolsuses
  • ttp T1059.006 Pythonuses
  • ttp T1552.001 Credentials In Filesuses
  • ttp T1041 Exfiltration Over C2 Channeluses
  • ttp T1528 Steal Application Access Tokenuses
  • ttp T1105 Ingress Tool Transferuses
  • ttp T1071.001 Web Protocolsuses
  • ttp T1021 Remote Servicesuses
  • ttp T1098 Account Manipulationuses
  • ttp T1027 Obfuscated Files or Informationuses
Read the full analysis →
SafeDep Logo
SafeDep
Terms · Privacy Policy · Cookie Preferences
SOC 2 Type II Certified
ISO 27001:2013 Certified
SOC 2 Type II Certified
ISO 27001:2013 Certified
SOC 2 Type II Certified
ISO 27001:2013 Certified
Product
  • Features
  • Pricing
  • How it works
Solutions
  • AI Agent Discovery
  • AI Agent Monitoring
  • Threat Intel for Agents
  • Threat Intel for SecOps
  • MCP Server
  • Endpoint Protection
  • Threat Intel Data Hub
  • Developer API
  • Partners
Support
  • Docs
  • Community Forum
  • FAQ
  • Professional Services
  • Status
Company
  • About
  • Blog
  • Contact
  • Careers
  • GitHub
© 2026 SafeDep, Inc. All rights reserved
Join us on Discord
We value your privacy

SafeDep keeps analytics anonymous and cookie-free until you opt in. Accepting helps us understand product usage and improve your experience. Privacy Policy

Choose what you share. You can change this anytime from the footer.

Essential Always on
Remembers your cookie choice and keeps the site secure. Cannot be switched off.
Analytics
PostHog + Google Analytics. Page views, feature usage and CTA clicks to improve the product.