WeSearch

Shai-Hulud Themed Malware Found in the PyTorch Lightning AI Training Library

·4 min read · 0 reactions · 0 comments · 3 views
Shai-Hulud Themed Malware Found in the PyTorch Lightning AI Training Library

The PyPI package lightning was compromised in versions 2.6.2 and 2.6.3 with Mini Shai-Hulud themed malicious code to execute credential-stealing malware on import.

Original article
Semgrep
Read full at Semgrep →
Opening excerpt (first ~120 words) tap to expand

The PyPI package 'lightning', a widely-used deep learning framework, was compromised in a supply chain attack affecting versions 2.6.2 and 2.6.3 published on April 30, 2026. Teams building image classifiers, fine-tuning LLMs, running diffusion models, or developing time-series forecasters frequently have lightning somewhere in their dependency tree. Running pip install lightning is all that is needed to activate. The malicious versions contain a hidden _runtime directory with obfuscated JavaScript payload that executes automatically upon module import. The attack steals credentials, authentication tokens, environment variables, and cloud secrets, while also attempting to poison GitHub repositories.

Excerpt limited to ~120 words for fair-use compliance. The full article is at Semgrep.

Anonymous · no account needed
Share 𝕏 Facebook Reddit LinkedIn Threads WhatsApp Bluesky Mastodon Email

Discussion

0 comments

More from Semgrep