Back to blog
Case study
Case Study: PyTorch / torchtriton Dependency Confusion
· 1 min read
sources (the PyTorch advisory) before publishing.
Around the end of 2022, users who installed the PyTorch nightly build briefly pulled a malicious package called torchtriton, a textbook dependency-confusion attack.