Attackers compromised the popular Python Lightning package and published two trojanized versions capable of stealing credentials, with four cybersecurity firms confirming the supply chain intrusion affected versions 2.6.2 and 2.6.3 released on April 30, 2026.