Malware Attack Targets Popular Python Package, Credential Theft Confirmed
On April 30, 2026, a significant malware attack compromised the widely-used Python package Lightning, releasing two malicious versions aimed at stealing user credentials. The attack is believed to be linked to the ongoing Mini Shai-Hulud campaign, which has previously targeted other software packages.
The affected versions, 2.6.2 and 2.6.3, have been quarantined by the Python Package Index (PyPI) administrators. Users of the open-source PyTorch Lightning framework, which boasts over 31,100 stars on GitHub, are at risk. The malware operates silently, executing harmful code as soon as the package is imported.
To protect against this threat, users should immediately block and uninstall the compromised versions, reverting to version 2.6.1. Additionally, it’s crucial to rotate any exposed credentials.
Given the potential for widespread impact, the risk level of this incident is considered High.
Source: View Original Report
