MIT TRACE

MIT CTL Logo
Back to Main Dashboard

PyTorch Lightning PyPI releases compromised in supply-chain attack

On 30 April 2026 an attacker captured PyPI credentials and used them to publish compromised PyTorch Lightning versions 2.6.2 and 2.6.3. Lightning AI said the malicious releases were installable for 42 minutes before quarantine and that the distribution layer, not the source repository, was compromised, creating a direct software-supply-chain data-integrity impact.

69

Estimated severity

69 / 100

92

Source reliability

92 / 100

Approximate Date

30/04/2026

Targeted Company

LIGHTNING AI

Targeted Company Supply Chain Impact

  1. Distribution & Fulfillment

  2. Procurement & Sourcing

  3. Production & Manufacturing

  4. Sales (Retail & Ecommerce)

  5. Warehousing

  6. Service Delivery

  7. Unrecognized Impact

Supply Chain Relations

No information

Geographic Impact

Country Targeted Company

Country visual unavailable

No information

Other Affected Countries

No other affected countries reported

Target country

No information

Affected countries

No information

Impacted regions

No information

Operational Impact

Duration

No information

Financial impact (USD M)

No information

Impact types

Supply chain data integrity impact

Affected sectors

Technology & IT Services

Affected departments

Information Technology

Attack Profile

Attack types

Software supply chain compromiseMalwareUse of stolen credentials

Attributed threat actors

No information

Sources

Please rotate your phone

MIT TRACE is optimized for landscape orientation on mobile.