Trojaned PyTorch Lightning hits PyPI: what to rotate this week

Person at a desk with multiple monitors showing code in a dark room — photo by Tima Miroshnichenko on Pexels

Yesterday afternoon, Semgrep’s research team disclosed that versions 2.6.2 and 2.6.3 of lightning — the PyPI distribution of PyTorch Lightning, the standard high-level training wrapper used by tens of thousands of ML projects — were trojaned. Anyone who ran pip