IncidentTwo Malicious Versions: How a Stored API Token Compromised PyPI's Lightning Package
Incident Overview Versions 2.6.2 and 2.6.3 of the lightning package on PyPI were compromised with malicious code. An attacker exploited a stored API token to publish these versions without authorizati














