THREATPKG
SYNC STALE

Supply-chain threat intelligence

Incident detail

criticalpypi·maintainer compromise·osv

Malicious code in lightning (PyPI)

lightning

Risk score

92

AI summary

Indexed incident for lightning (pypi).

Description

Versions 2.6.2, 2.6.3 were compromised.

Compromised versions contain injected code that starts automatically during importing the module, downloads (legitimate) JavaScript runtime, and executes included JavaScript infostealer. It collects credentials from multiple sources (e.g. files, process memory, cloud metadata endpoints, CLI commands like gh or gcloud), sensitive cryptocurrency data, shell history files. It also attempts to spread itself using discovered credentials to other repositories and packages.


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-04-compr-lightning

Reasons (based on the campaign):

  • infostealer

  • files-exfiltration

  • exfiltration-ssh-keys

  • exfiltration-crypto

  • exfiltration-credentials

  • compromised-package

Technical details

Affected versions

=2.6.2=2.6.3

Indicators

  • affected version=2.6.275%
  • affected version=2.6.375%

Timeline

  1. Advisory published
  2. Indexed by ThreatPkg

Related incidents