lightning PyPI Package Compromised in Supply Chain Attack
Blog post from Socket
The PyPI package "lightning" has been compromised in a supply chain attack, impacting versions 2.6.2 and 2.6.3 with malicious code, while version 2.6.1 remains clean. This attack affects a widely used deep learning framework, leading to potential credential theft, GitHub repository poisoning, and npm package infections. The malicious package features a hidden directory that automatically executes a JavaScript payload on import, requiring no user action. The compromise is linked to suspicious activity in the project's GitHub account, including unauthorized branch operations, indicating a possible account compromise. The attack shares similarities with the Shai-Hulud compromises, suggesting the use of stolen credentials for both PyPI publication and GitHub suppression. A group called Team PCP has claimed responsibility, with the operation allegedly involving broader extortion activities and connections to other groups like LAPSUS$. Immediate actions recommended by Socket include blocking the compromised versions, removing them from systems, rotating exposed credentials, and auditing affected environments for unauthorized activity. The attackers appear to have attempted but failed to expand beyond the "lightning" package due to repository controls, while further analysis on the attack's scope and connections is ongoing.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 2 | 1,821 | 338 | 111 | +22% |
| AI Coding Assistant | 1 | 1,480 | 382 | 153 | +18% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.