The popular PyPI package lightning experienced a supply chain attack affecting versions 2.6.2 and 2.6.3, published on April 30, 2026. The compromise introduced malicious code that executes automatically upon module import, downloading Bun JavaScript runtime and executing an 11MB obfuscated payload. The attack harvests credentials including GitHub tokens, npm tokens, cloud credentials from AWS, Azure, and Google Cloud, while targeting CI/CD environments. The malicious code poisons GitHub repositories by injecting backdoored files impersonating Claude Code commits and infects local npm packages through tarball manipulation. The attack shows similarities to previous Shai-Hulud campaigns in terms of credential targeting and obfuscation methods. Evidence suggests the maintainer's GitHub account (pl-ghost) was compromised, with suspicious branch operations and disclosure suppression indicating ongoing attacker control. The incident affects a widely-used deep learning framework receiving millions of monthly downl...
Executive Summary
Team Pcp is a sophisticated threat actor targeting supply chains through PyPI packages, compromising widely used libraries like Lightning to inject malicious code. Their primary focus appears to be credential harvesting and disrupting CI/CD environments, with similarities to the Shai-Hulud campaign.
Goals & Targeting
Team Pcp aims to harvest credentials and disrupt software supply chains, likely to gain long-term access or intelligence. Their targeting of widely used libraries suggests a focus on maximizing impact and persistence in critical IT ecosystems. Typical victims include organizations utilizing popular Python packages and CI/CD tools.
Enhanced Description
Team Pcp leverages supply chain attacks by compromising Python Package Index (PyPI) packages such as Lightning. They injected malicious code into versions 2.6.2 and 2.6.3, which executes upon import, downloading an obfuscated payload (11MB) delivered via the Bun JavaScript runtime. This attack harvests GitHub, npm, and cloud credentials from AWS, Azure, and Google Cloud, targeting CI/CD environments. Attackers impersonated Claude Code commits to poison GitHub repositories and manipulate npm tarballs, indicating high sophistication. The campaign shows parallels with Shai-Hulud's credential-targeting tactics.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Team Pcp's campaign demonstrates a focus on disrupting critical software supply chains. They likely use compromised maintainer accounts to insert malicious code, as seen with GitHub account 'pl-ghost'. This incident highlights their ability to manipulate trusted repositories and packages, suggesting ongoing operations beyond this event.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in their existence and activities based on the attack's detailed evidence. Limited data exists beyond this incident, so uncertainty remains about their full capabilities.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics