Malicious PyTorch Lightning Packages Found on PyPI
ID: c1cc61dc-f476-5a4a-b63b-4bc3a7a9777c
STIX ID: report--c1cc61dc-f476-5a4a-b63b-4bc3a7a9777c
Feed Name: Security Boulevard
Two malicious versions of the widely used pytorch‑lightning package (2.6.2 and 2.6.3) were published to PyPI on April 30, 2026 after the maintainer account was compromised. The packages contain code that executes on import to steal developer credentials and automatically republish infected packages to repositories where the stolen tokens grant access, representing a self‑propagating open‑source supply‑chain malware campaign. Users are advised to verify they are using version 2.6.1 and follow the project's advisory.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
