A recent wave of supply chain attacks has successfully infiltrated the widely-used Python package, PyTorch Lightning, resulting in the release of two harmful versions designed to capture user credentials. Security firms, including Aikido Security, OX Security, Socket, and StepSecurity, reported that these compromised versions, identified as 2.6.2 and 2.6.3, were uploaded on April 30, 2026. The nature of this attack highlights the ongoing vulnerabilities in software supply chains, where attackers can manipulate trusted packages to distribute malware. Users of PyTorch Lightning are urged to verify their installations and update to secure versions to safeguard their credentials against potential theft. This incident underscores the critical need for enhanced security measures within the software development lifecycle, as attackers increasingly target popular libraries and frameworks to exploit unsuspecting users.
Supply Chain Breach Targets PyTorch Lightning and Intercom-client for Credential Theft
Recent supply chain attacks have compromised the PyTorch Lightning package, leading to the distribution of malicious versions aimed at stealing user credentials.
