---
id: 20260501-T0-13
title: "PyTorch Lightning发现沙丘主题恶意代码"
title_en: "Malicious Code Found in PyTorch Lightning"
url: https://ai.daily.yangsir.net/daily/20260501-T0-13
issue_date: 2026-05-01
publish_date: 2026-04-30T16:09:26.000Z
category: news
source_name: "HN AI 精选"
source_url: https://semgrep.dev/blog/2026/malicious-dependency-in-pytorch-lightning-used-for-ai-training/
---

# PyTorch Lightning发现沙丘主题恶意代码

AI训练库PyTorch Lightning被植入沙丘主题恶意代码。该代码可窃取训练数据，影响全球超5000个项目。安全团队已发布补丁，建议用户立即升级到最新版本。黑客通过第三方库传播漏洞。

## English Version

**Malicious Code Found in PyTorch Lightning**

AI training library PyTorch Lightning compromised with Dune-themed malware. Code steals training data, affecting over 5,000 projects globally. Security team issued patch; users should update immediately. Hackers spread vulnerability via third-party libraries.

---

**来源**：[HN AI 精选](https://semgrep.dev/blog/2026/malicious-dependency-in-pytorch-lightning-used-for-ai-training/)

**详情页**：https://ai.daily.yangsir.net/daily/20260501-T0-13

---

*智语观潮 · Daily — https://ai.daily.yangsir.net/llms.txt*