PyPI Package Compromised in Supply Chain Attack
Reported 30 Apr 2026 by otx · Severity: medium
The popular PyPI package lightning experienced a supply chain attack affecting versions 2.6.2 and 2.6.3, published on April 30, 2026. The compromise introduced malicious code that executes automatically upon module import, downloading Bun JavaScript runtime and executing an 11MB