Malicious Lightning 2.6.2/2.6.3 released April 30 enable credential theft via hidden payload, leading to PyPI quarantine and ...
On April 30, 2026, someone slipped credential-stealing malware into two freshly published versions of PyTorch Lightning, one ...
A malicious version of the PyTorch Lightning package published on the Python Package Index (PyPI) delivers a ...
Two recent PyTorch Lightning releases on PyPI were found to contain credential-stealing malware capable of self-propagation. The malicious code targeted developer tokens, API keys, and cloud ...