PyPI Package 'Lightning' Compromised in Supply Chain Attack Affecting AI/ML Developers
By
Isaac Evans
Solid neighbourhood-bakery energy. Trustworthy and warm.
Summary
The PyPI package 'lightning', a widely-used deep learning framework, was compromised in a supply chain attack affecting versions 2.6.2 and 2.6.3 published on April 30, 2026. The malicious versions contain a hidden _runtime directory with obfuscated JavaScript payload that executes automatically upon module import, deploying credential-stealing malware themed as "Mini Shai-Hulud" (a Dune reference). Teams building image classifiers, fine-tuning LLMs, running diffusion models, or developing time-series forecasters are at risk since lightning is commonly in their dependency tree.
Key quotes
· 4 pulledThe PyPI package 'lightning', a widely-used deep learning framework, was compromised in a supply chain attack affecting versions 2.6.2 and 2.6.3 published on April 30, 2026.
Teams building image classifiers, fine-tuning LLMs, running diffusion models, or developing time-series forecasters frequently have lightning somewhere in their dependency tree.
Running pip install lightning is all that is needed to activate.
The malicious versions contain a hidden _runtime directory with obfuscated JavaScript payload that executes automatically upon module import.
You might also wanna read
Microsoft uncovers supply chain attack: Compromised @antv npm packages steal CI/CD credentials via Mini Shai-Hulud malware
Microsoft has identified an active supply chain attack targeting the @antv npm package ecosystem. A threat actor compromised an @antv mainta

September 2025 NPM supply-chain attack compromises popular JavaScript packages
In September 2025, a coordinated software supply-chain attack targeted multiple popular NPM packages in the JavaScript ecosystem. The attack
Microsoft uncovers npm supply chain attack stealing cloud and CI/CD credentials via typosquatted packages
Microsoft identified an active supply chain attack (Mini Shai-Hulud campaign) targeting the npm package ecosystem. On May 28, 2026, a threat
North Korean Chollima Group Targets PHP Developers via Malicious Packagist Package
A malicious obfuscated JavaScript payload was discovered appended to tailwind.js in the Packagist development version dev-drewroberts/featur
