{
"$type": "site.standard.document",
"bskyPostRef": {
"cid": "bafyreiefuc4ptc7cxaqvws4ortkcjetejxrdliicjby4yb5eccaeqgpdbi",
"uri": "at://did:plc:6wtxqaikjf62unmnajbfbq5v/app.bsky.feed.post/3mkzn6l72wlj2"
},
"coverImage": {
"$type": "blob",
"ref": {
"$link": "bafkreievv7cbeixbj2tsxmsqeviox3fmkty4ildxkje5n2wd5yozpvk5ji"
},
"mimeType": "image/png",
"size": 152199
},
"path": "/pytorch-lightning-and-intercom-packages-hit-by-credential-stealing-supply-chain-attack/",
"publishedAt": "2026-05-03T14:57:50.000Z",
"site": "https://vpncentral.com",
"tags": [
"News",
"PyTorch Lightning and Intercom packages hit by credential-stealing supply chain attack",
"VPN Central"
],
"textContent": "A new supply chain attack has hit the Python, npm, and PHP package ecosystems, with malicious versions of Lightning and Intercom packages used to steal developer credentials and spread through repositories. The main affected Lightning versions are 2.6.2 and 2.6.3, which were pushed to PyPI on April 30, 2026. The project’s advisory says these versions […]\n\nThe post PyTorch Lightning and Intercom packages hit by credential-stealing supply chain attack appeared first on VPN Central.",
"title": "PyTorch Lightning and Intercom packages hit by credential-stealing supply chain attack"
}