logo

Malicious PyTorch Lightning Packages Found on PyPI

ID: c1cc61dc-f476-5a4a-b63b-4bc3a7a9777c

STIX ID: report--c1cc61dc-f476-5a4a-b63b-4bc3a7a9777c

Feed Name: Security Boulevard

Threat Score
80/100

Date Published: 2026-05-01

Date Updated: 2026-05-01

Author: Sonatype Security Research Team

...
...

Two malicious versions of the widely used pytorch‑lightning package (2.6.2 and 2.6.3) were published to PyPI on April 30, 2026 after the maintainer account was compromised. The packages contain code that executes on import to steal developer credentials and automatically republish infected packages to repositories where the stolen tokens grant access, representing a self‑propagating open‑source supply‑chain malware campaign. Users are advised to verify they are using version 2.6.1 and follow the project's advisory.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.