216.73.216.6

Compromised ultralytics PyPI package delivers crypto coinminer

· Published 07/12/2024 12:25 · Modified 09/12/2024 11:31

Export JSON

Essential information

Published
07/12/2024 12:25
Modified
09/12/2024 11:31
Tags
2024-12-07 coinminer pypi supply chain attack ultralytics xmrig
Related entities
14 techniques (mitre), 1 malware

Description

A malicious version of the popular AI library was published on , containing downloader code for the . The compromise was achieved by exploiting a known GitHub Actions script injection. Two versions, 8.3.41 and 8.3.42, were affected before a clean version 8.3.43 was released. The attack had potential to impact millions of users due to the package's popularity. The infection vector involved crafting malicious pull requests to gain backdoor access. The compromise was initiated from Hong Kong. The malicious code was inserted into downloads.py and model.py files, designed to download platform-specific payloads. While this incident focused on cryptocurrency mining, it could have been used to deploy more aggressive malware.

External references