PyTorch Lightning Compromised in PyPI Supply Chain Attack to Steal Credentials
9/10Python package PyTorch Lightning versions 2.6.2 and 2.6.3 were compromised in a supply chain attack reported on April 30, 2026, by Aikido Security, Socket, and StepSecurity, aiming to steal credentials. This incident exposes increasing risks in software supply chains.
