Cyber News / Article / Malicious PyTorch dependency 'torchtriton' on PyPI: everything you need to know

Malicious PyTorch dependency 'torchtriton' on PyPI: everything you need to know
The developers of PyTorch (a popular machine-learning framework) recently identified a malicious dependency confusion attack on the open-source project. Security teams are advised to check for infected resources and rotate any exposed keys.
A package calledtorchtritonwas uploaded to the Python Package Index (PyPI) code repository, with the same name as the package shipped on the PyTorch nightly package index. Due to the way pip (a package-management system for Python) handles package installation, the malicious version was being installed by default, instead of the legitimate version from the official repository. This means that anyone who downloaded the nightly build between December 25, 2022 and December 30, 2022 infected their machine. Security teams are advised to look for contaminated resources and rotate any discovered keys.
The creator of the copied package hasstatedthey had no malicious intent and have since deleted all the collected data. Given this claim has not been verified, it is still highly recommended to uninstall the package if the nightly build was installed during the relevant period and revoke any secrets that were stored on impacted resources.
The malicious version oftorchtritonwas ultimately removed from PyPi and replaced with a placeholder package namedpytorch-triton.
Dependency confusion is a technique used to exploit the software supply chain by injecting unwanted and potentiallymalicious codevia vulnerable package managers and code repositories.
Open-source projects can be susceptible to dependency confusion attacks as a result of misconfigurations, particularly if they list their own internal versions of packages as dependencies but don't claim dummy versions or namespaces on public repositories. For example, two npm packages that were previously used by AWS and later delisted werereclaimed by attackersand replaced with fake versions that injected malicious code to exfiltrate user information.
In this case, a package calledtorchtritonwas uploaded to the PyPi repository with the exact same name as a package shipped on the PyTorch nightly package index. The attacker took advantage of pip’s behavior, which prioritizes packages listed on PyPi over other available versions when using theextra-index-urlargument.
The package was downloaded over3,000 timesbefore it was taken down, whereas the main PyTorch packagetorchthat lacks the malicious code was downloaded approximately1.5 million timesduring the same period.
Thetorchtritonpackage that was uploaded to the PyPI repository differs from the legitimate version in that it contains a malicious binary calledtritonthat was installed in the pathPYTHON_SITE_PACKAGES/triton/runtime/triton.
nameservers from/etc/resolv.conf
hostname fromgethostname()
current username fromgetlogin()
current working directory name fromgetcwd()
environment variables
Additionally, it copies information from the following files:
/etc/hosts
/etc/passwd
The first 1,000 files in$HOME/*
$HOME/.gitconfig
$HOME/.ssh/
The malware then uploads all this information, including file contents, via DNS tunneling to the domain.h4ck[.]cfdusing the DNS serverwheezy[.]io.
SHA256 hash of the malicious package -2385b29489cd9e35f92c072780f903ae2e517ed422eae67246ae50a5cc738a0e
SHA1 hash of the malicious package -9c89731a94dd4f2a594a22c1b171cb6c20f55e41
PyTorch-nightly on Linux installed via pip between December 25, 2022 and December 30, 2022.
Users of the PyTorch stable packages are not affected by this issue.
The PyTorch developers have recommended using the following command to check whether the malicious binary has been included in thetorchtritonpackage in your current Python environment:
Note that the malicious binary is only executed when the triton package is imported, which requires explicit code and does not reflect PyTorch’s default behavior.
If you suspect your environment is affected, you can run these commands to uninstall the package:
Impacted organizations are advised toscan for secretsin any affected resources and rotate any discovered keys.
Wiz customers can use thepre-built queryand advisory in the Wiz Threat Center to search for infected instances in their environment.
PyTorch advisory
Critical RCE vulnerability found in Linux kernel's `ksmbd` module: remote attackers can execute code without authentication. The module is not enabled by default on most operating systems.
A new exploit method targeting CVE-2022-41080 and CVE-2022-41082 vulnerabilities in Exchange servers, which can bypass previous workarounds, has been discovered and exploited in the wild. Organizations should patch urgently.
Wiz enhances its Dynamic Scanner to detect publicly exposed, unauthenticated APIs
Get a personalized demo
©2026Wiz, Inc.
StatusPrivacy PolicyTerms of UseModern Slavery StatementCookie Settings
Related articles
Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code
9 days ago
Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages
9 days ago
BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access
9 days ago
You might Also like

Windows BitLocker Vulnerability Allows Attackers to Execute Malicious Code Remotely

Man gets 15 years for extorting women with AI-generated porn videos

