Skip to content

Compromised PyTorch-nightly dependency chain between December 25th and December 30th, 2022

PyTorch Foundation. (2022). Compromised PyTorch-nightly dependency chain between December 25th and December 30th, 2022.

Type
Web resource
Intellectual base
Web
Year
2022
Link
https://pytorch.org/blog/compromised-nightly-dependency/

Cited by

1 citation across 1 artifact.

Each citation links to the sentence it supports in the citing article.

Domain-specific

  • AI Supply-Chain Attack
    • A real incident hit the PyTorch ecosystem in December 2022

      This sourceDescribes the December 2022 PyTorch-nightly compromise as dependency confusion: because the public PyPI index took precedence, the nightly install pulled a malicious torchtriton instead of PyTorch's own.

      SupportedVerified against a saved copy of the source

      “Compromised PyTorch-nightly dependency chain between December 25th and December 30th, 2022.”

      From a saved copy of the source.

      Read by an automated reader; not a human review. How support was checked

Verification

Does it exist? Not checked yet. This entry carries no identifier to resolve. It was extracted from the citation as written in the article, normalized, and deduplicated against the rest of the registry.

Does it back the claim? Read against the text for 1 of 1 citation: 1 supported. Each verdict is shown under its citation below, with what in the work backs the sentence.

Support is checked per citation rather than per work — the same source can be cited soundly in one article and wrongly in another. Per-citation recording began recently, so a citation with no recorded check is a gap in the record rather than evidence it went unchecked.

See how references were verified.

Registry ID ref:79db7a9a134e · see in the full table