Hacker News new | ask | show | jobs
PyTorch Lightning project quarantined by PyPI (pypi.org)
6 points by grepLeigh 46 days ago
3 comments

Malicious versions are 2.6.2 and 2.6.3: https://socket.dev/blog/lightning-pypi-package-compromised
That's really bad.
Supply chain attack? Does anyone have more info?