
semgrep.dev
April 30, 2026
6 min read
58/100
Summary
The PyPI package 'lightning', versions 2.6.2 and 2.6.3, was compromised in a supply chain attack, affecting users of the PyTorch Lightning AI training library. The malicious versions include a hidden _runtime directory containing obfuscated JavaScript that activates upon running pip install lightning.
Key Takeaways
Community Sentiment
Concerns

Axios compromised on NPM – Malicious versions drop remote access trojan
Mar 31, 2026

Notepad++ supply chain attack breakdown
Feb 3, 2026

Glassworm Is Back: A New Wave of Invisible Unicode Attacks Hits Repositories
Mar 15, 2026
![[Security]: CRITICAL: Malicious litellm_init.pth in litellm 1.82.8 — credential stealer · Issue #24512 · BerriAI/litellm](https://pub-90f0ac00d93c47daac3e1d2cdd28d496.r2.dev/articles/51d46f16909604153de11fd523630f79.webp)
LiteLLM Python package compromised by supply-chain attack
Mar 24, 2026

We May Be Living Through the Most Consequential Hundred Days in Cyber History
Apr 13, 2026