The PyTorch Lightning AI training library was compromised in versions 2.6.2 and 2.6.3 with malware that steals credentials and attempts to poison GitHub repositories. The malware is themed around Shai-Hulud and is believed to be the work of the same threat actor behind the mini Shai-Hulud campaign. The malicious code was not submitted to the main GitHub repository, but was instead published directly to PyPI using compromised credentials. Users are advised to use version 2.6.1 until a patched version is released.