Country visual unavailable
No information
On 30 April 2026 an attacker captured PyPI credentials and used them to publish compromised PyTorch Lightning versions 2.6.2 and 2.6.3. Lightning AI said the malicious releases were installable for 42 minutes before quarantine and that the distribution layer, not the source repository, was compromised, creating a direct software-supply-chain data-integrity impact.
Estimated severity
69 / 100
Source reliability
92 / 100
Approximate Date
30/04/2026
Targeted Company
LIGHTNING AI
Distribution & Fulfillment
Procurement & Sourcing
Production & Manufacturing
Sales (Retail & Ecommerce)
Warehousing
Service Delivery
Unrecognized Impact
Supply Chain Relations
No information
Country visual unavailable
No information
No other affected countries reported
Target country
No information
Affected countries
No information
Impacted regions
No information
Duration
No information
Financial impact (USD M)
No information
Impact types
Affected sectors
Affected departments
Attack types
Attributed threat actors
No information
Please rotate your phone