
The Hacker News
Security•2026-04-30
PyTorch Lightning Compromised in PyPI Supply Chain Attack to Steal Credentials
PyTorch Lightning, a popular Python framework with over 31,100 GitHub stars, was compromised in a supply chain attack with two malicious versions (2.6.2 and 2.6.3) deployed to conduct credential theft.