Popular PyTorch Lightning Package Compromised by Mini Shai-Hulud
ID: d957722f-9ab4-5589-875f-0fd3b765b9e4
STIX ID: report--d957722f-9ab4-5589-875f-0fd3b765b9e4
Feed Name: Aikido Security's Blog
A supply-chain malware campaign has been discovered in the PyPI 'lightning' package (versions 2.6.2 and 2.6.3). Malicious code injected into __init__.py spawns a background thread to run start.py, which fetches and executes a Bun-based payload (router_runtime.js) that steals SSH keys, shell histories, cloud credentials, docker/kubernetes configs, npm tokens, and numerous cryptocurrency wallets; stolen data is RSA-2048 encrypted and exfiltrated to public GitHub repositories. The report provides SHA256 hashes for router_runtime.js and start.py, IOCs, and detection/mitigation advice, and recommends treating infected machines as compromised.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
