In yet another software supply chain attack, threat actors
have managed to compromise the popular Python package Lightning to
push two malicious versions to conduct credential theft. According
to Aikido Security, Socket, and StepSecurity, the two malicious
versions are versions 2.6.2 and 2.6.3, both of which were published
on April 30, 2026. The campaign is assessed to be an extension of
the
Read more https://thehackernews.com/2026/04/pytorch-lightning-compromised-in-pypi.html

