logo

Popular Python Package lightning Hacked in Supply Chain Attack

ID: c81f798c-fdb2-5d5d-9801-425256f7a43a

STIX ID: report--c81f798c-fdb2-5d5d-9801-425256f7a43a

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-04-30

Date Updated: 2026-04-30

Author: Guru Baran

...
...

Socket Research Team reports that the PyPI package 'lightning' (PyTorch Lightning) was compromised: versions 2.6.2 and 2.6.3 contain a hidden _runtime directory with a multi-stage, obfuscated credential-stealing payload that executes on import, exfiltrates GitHub/NPM/cloud tokens, and can poison NPM packages; community reports and rapid issue closure indicate a possible GitHub maintainer account takeover. Immediate actions recommended include removing the malicious versions, downgrading to 2.6.1, rotating all credentials, and auditing repositories, CI/CD pipelines, and build environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.