Yesterday we saw a supply-chain attack on PyTorch Lightning (on Pypi, not our core repo). It's wild how it happened but it was caught and quarantined within 42 minutes thanks to the open source community.
It's one reason why open source actually helps increase the security posture of projects. Thank you to
@pypi and
@SocketSecurity ⚡️
Summary: On April 30th, 2026, an attacker captured PyPI credentials and used them to push compromised versions of PyTorch Lightning (PTL).
These versions were live for 42 minutes before PTL community members alerted us and PyPI quarantined the package. The PyTorch Lightning GitHub source code repository was never compromised. This affected those who installed PTL via PyPI between 12:45:20 and 13:27:30 UTC on April 30th, 2026.