MAL-2026-3201
Dashboard / Malicious Package / MAL-2026-3201
MAL-2026-3201
Summary: Malicious code in lightning (PyPI)
Details: Source: kam193 (703ac419d775488be137d7e01517d768da0b5581ab63338fb9523f2289f2b92c) Versions 2.6.2, 2.6.3 were compromised. Compromised versions contain injected code that starts automatically during importing the module, downloads (legitimate) JavaScript runtime, and executes included JavaScript infostealer. It collects credentials from multiple sources (e.g. files, process memory, cloud metadata endpoints, CLI commands like gh or gcloud), sensitive cryptocurrency data, shell history files. It also attempts to spread itself using discovered credentials to other repositories and packages. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-04-compr-lightning Reasons (based on the campaign): - infostealer - files-exfiltration - exfiltration-ssh-keys - exfiltration-crypto - exfiltration-credentials - compromised-package
References: https://github.com/Lightning-AI/pytorch-lightning/issues/21691, https://www.aikido.dev/blog/pytorch-lightning-pypi-compromise-mini-shai-hulud, https://socket.dev/blog/lightning-pypi-package-compromised, https://bad-packages.kam193.eu/pypi/campaign/2026-04-compr-lightning, https://github.com/Lightning-AI/pytorch-lightning/security/advisories/GHSA-w37p-236h-pfx3
Affected packages
Package
Name: lightning
Purl: pkg:pypi/lightning
Affected ranges
Type: N/A
Events:
