logo

AI’s Supply Chain Nightmare: The Lightning Framework Worm and the “Silence Developer” Meme

ID: 54689d6e-b688-5520-a9c0-aa229c0f7338

STIX ID: report--54689d6e-b688-5520-a9c0-aa229c0f7338

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-05-02

Date Updated: 2026-05-02

Author: Ddos

...
...

Security researchers report that Lightning versions 2.6.2 and 2.6.3 were backdoored with a self‑propagating worm that executes on import, downloads the Bun JavaScript runtime, and runs an obfuscated payload which harvests GitHub/npm/cloud credentials, poisons repositories, and injects postinstall hooks into npm tarballs to spread; the attackers also appear to have compromised a maintainer GitHub account and posted Tor links claiming ties to extortion groups. Socket recommends immediate removal of the malicious releases, downgrading to 2.6.1, rotating exposed credentials, auditing repositories for unauthorized commits and hidden directories, and inspecting local npm artifacts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.