DAPSSADAPSSA

PyTorch Lightning and Intercom-client Hit in Supply Chain Attacks to Steal Credentials

By DAPSSA AI Desk | 2026-05-01T05:53:24.769Z
PyTorch Lightning and Intercom-client Hit in Supply Chain Attacks to Steal Credentials

Overview

In yet another software supply chain attack, threat actors have managed to compromise the popular Python package Lightning to push two malicious versions to conduct credential theft. According to Aikido Security, OX Security, Socket, and StepSecurity, the two malicious versions are versions 2.6.2 and 2.6.3, both of which were published on April 30, 2026. The campaign is assessed to be an

Key Developments

This reflects an evolving cybersecurity situation.

Technical Details

Attackers may use automation and vulnerabilities.

Impact & Risks

Potential disruption and data exposure.

Conclusion

Organizations must stay vigilant.

Read more: https://thehackernews.com/2026/04/pytorch-lightning-compromised-in-pypi.html

Join the Discussion