VerifiVerifi Security
Products
Use cases
Resources
Pricing
Company
ResourcesGet Started
Back to blog
Case study

Case Study: PyTorch / torchtriton Dependency Confusion

· 1 min read

sources (the PyTorch advisory) before publishing.

Around the end of 2022, users who installed the PyTorch nightly build briefly pulled a malicious package called torchtriton, a textbook dependency-confusion attack.

What happened

Why it worked

What defenders learn

How Verifi prevents dependency confusion →

Related
  • Dependency Confusion, Explained
  • Malicious Install Scripts
  • What Is a Registry Firewall?
More from the blog
Case study

Case Study: The Codecov Bash Uploader Compromise

Case study

Case Study: The event-stream Incident

Get the latest on supply-chain threats

New malicious packages and IOCs, straight from the corpus. No spam.

Products
  • Overview
  • Verifi CLI
  • Verifi Firewall
  • Verifi Intel
  • Verifi CodeFix
  • Verifi Workflows
Use cases
  • Block malicious packages
  • Catch novel threats
  • Incident response
  • Cut alert noise
  • Prove compliance
Resources
  • All articles
  • Supply-chain 101
  • Glossary
  • FAQ
  • MITRE ATT&CK
Company
  • Why Verifi
  • Platform
  • Trust and security
  • Compliance
  • Pricing
  • Contact
VerifiVerifi Security© 2026. All rights reserved.
ProductsResearchContact
© 2026 Verifi Security.