Junglewise Threat Intelligence

CVE-2026-44484: PyTorch Lightning malicious code injection in PyPI packages

CVE-2026-44484 · Severity: critical · CVSS 9.8 · Published 2026-05-14

Technologies: lightning (PyPI), pytorch-lightning (PyPI). Vendors: PyPI.

Executive brief

PyTorch Lightning, a popular framework for building AI models, has identified that versions 2.6.2 and 2.6.3 of its software were compromised with malicious code. This code is designed to steal sensitive credentials, such as API keys and access tokens, from systems where the software is installed. Organizations using these versions should immediately rotate all secrets and revert to a safe version to prevent unauthorized access to their infrastructure and data.

Technical details

A supply chain compromise affected the PyTorch Lightning package on the Python Package Index (PyPI). Malicious code was embedded in versions 2.6.2 and 2.6.3, categorized as CWE-506 (Embedded Malicious Code). The malicious functionality is designed for credential harvesting, targeting API keys, SSH keys, and access tokens within the environment where the package is executed. The attack vector is network-based as the package is distributed via public repositories, and no specific user interaction or privileges are required beyond installing and running the affected library. The vendor has quarantined the affected versions and recommends pinning to version 2.6.1.

Affected products

  • Lightning-AI pytorch-lightning 2.6.2, 2.6.3

Timeline

  • 2026-04-30: disclosed: Initial discovery and advisory publication
  • 2026-05-07: advisory: GitHub Advisory published
  • 2026-05-12: other: Advisory last updated
  • 2026-05-14: other: NVD published date

References

Related threats