Popular Python Package lightning Hacked in Supply Chain Attack
ID: c81f798c-fdb2-5d5d-9801-425256f7a43a
STIX ID: report--c81f798c-fdb2-5d5d-9801-425256f7a43a
Feed Name: cybersecurityNews.com
Socket Research Team reports that the PyPI package 'lightning' (PyTorch Lightning) was compromised: versions 2.6.2 and 2.6.3 contain a hidden _runtime directory with a multi-stage, obfuscated credential-stealing payload that executes on import, exfiltrates GitHub/NPM/cloud tokens, and can poison NPM packages; community reports and rapid issue closure indicate a possible GitHub maintainer account takeover. Immediate actions recommended include removing the malicious versions, downgrading to 2.6.1, rotating all credentials, and auditing repositories, CI/CD pipelines, and build environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
