Socket @socket.dev · Apr 30

🚨 The popular PyPI package lightning has been compromised in a supply chain attack. Socket detected malicious code in versions 2.6.2 and 2.6.3 that executes automatically on import, downloads Bun, and runs an 11 MB obfuscated JavaScript payload designed to steal credentials.

4 likes 1 replies

?

Replies

Socket · Apr 30

Affected users should block lightning versions 2.6.2 and 2.6.3, downgrade to 2.6.1, rotate exposed secrets, and audit GitHub activity for suspicious commits. The project's GitHub account appears to be compromised, as they are closing reports of the attack. More details: socket.dev/blog/lightni...