
semgrep.dev
April 30, 2026
6 min read
67/100
Summary
The PyPI package 'lightning', versions 2.6.2 and 2.6.3, was compromised in a supply chain attack, affecting users of the PyTorch Lightning AI training library. The malicious versions include a hidden _runtime directory containing obfuscated JavaScript that activates upon running pip install lightning.
Key Takeaways
Community Sentiment
Concerns

Config Files That Run Code: Supply Chain Security Blindspot
Jun 8, 2026

Axios compromised on NPM – Malicious versions drop remote access trojan
Mar 31, 2026

Notepad++ supply chain attack breakdown
Feb 3, 2026

Glassworm Is Back: A New Wave of Invisible Unicode Attacks Hits Repositories
Mar 15, 2026

Anatomy of a Failed (Nation-State?) Attack
Jun 27, 2026