https://github.com/search?q=A%20Mini%20Shai-Hulud%20has%20Ap...
> The attack steals credentials, authentication tokens, environment variables, and cloud secrets, while also attempting to poison GitHub repositories.
https://github.com/Lightning-AI/pytorch-lightning/security/a...
Think twice before looking at a package and most importantly, always pin your dependencies.
achandra03•17m ago