logo

Popular PyTorch Lightning Package Compromised by Mini Shai-Hulud

ID: d957722f-9ab4-5589-875f-0fd3b765b9e4

STIX ID: report--d957722f-9ab4-5589-875f-0fd3b765b9e4

Feed Name: Aikido Security's Blog

Threat Score
90/100

Date Published: 2026-04-30

Date Updated: 2026-07-24

...
...

A supply-chain malware campaign has been discovered in the PyPI 'lightning' package (versions 2.6.2 and 2.6.3). Malicious code injected into __init__.py spawns a background thread to run start.py, which fetches and executes a Bun-based payload (router_runtime.js) that steals SSH keys, shell histories, cloud credentials, docker/kubernetes configs, npm tokens, and numerous cryptocurrency wallets; stolen data is RSA-2048 encrypted and exfiltrated to public GitHub repositories. The report provides SHA256 hashes for router_runtime.js and start.py, IOCs, and detection/mitigation advice, and recommends treating infected machines as compromised.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.