top of page
perceptive_background_267k.jpg

lightning: Obfuscated JavaScript Credential Stealer Bundled in PyPI Wheel

Published:

1 mei 2026 om 14:26:08

Alert date:

1 mei 2026 om 15:01:38

Source:

stepsecurity.io

Click to open the original link from this advisory

Supply Chain & Dependencies, Ransomware & Malware

A supply chain compromise was discovered in the lightning PyPI package versions 2.6.2 and 2.6.3 on April 30, 2026. The attack involved an obfuscated JavaScript credential stealer bundled within the Python package wheel. The project's GitHub account shows clear signs of compromise, with suspicious activity including rapid closure of security issue reports. This represents a significant supply chain attack targeting Python developers through the PyPI package repository. The malware is designed to steal user credentials through obfuscated JavaScript code embedded in what appears to be a legitimate Python package.

Technical details

Mitigation steps:

Affected products:

lightning PyPI package
PyPI

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page