Home / Companies / Socket / Blog / Post Details
Content Deep Dive

lightning PyPI Package Compromised in Supply Chain Attack

Blog post from Socket

Post Details
Company
Date Published
Author
Socket Research Team
Word Count
2,659
Company Posts That Month
32
Language
English
Hacker News Points
-
Post removed?
No
Summary

The PyPI package "lightning" has been compromised in a supply chain attack, impacting versions 2.6.2 and 2.6.3 with malicious code, while version 2.6.1 remains clean. This attack affects a widely used deep learning framework, leading to potential credential theft, GitHub repository poisoning, and npm package infections. The malicious package features a hidden directory that automatically executes a JavaScript payload on import, requiring no user action. The compromise is linked to suspicious activity in the project's GitHub account, including unauthorized branch operations, indicating a possible account compromise. The attack shares similarities with the Shai-Hulud compromises, suggesting the use of stolen credentials for both PyPI publication and GitHub suppression. A group called Team PCP has claimed responsibility, with the operation allegedly involving broader extortion activities and connections to other groups like LAPSUS$. Immediate actions recommended by Socket include blocking the compromised versions, removing them from systems, rotating exposed credentials, and auditing affected environments for unauthorized activity. The attackers appear to have attempted but failed to expand beyond the "lightning" package due to repository controls, while further analysis on the attack's scope and connections is ongoing.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 2 1,821 338 111 +22%
AI Coding Assistant 1 1,480 382 153 +18%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.