216.73.216.6

Malicious attack method on hosted ML models now targets PyPI

· Published 26/05/2025 09:17 · Modified 26/05/2025 09:49

Export JSON

Essential information

Published
26/05/2025 09:17
Modified
26/05/2025 09:49
Tags
2025-05-26 ai infostealer machine learning pickle format pypi pytorch supply chain attack
Related entities
2 observables, 8 techniques (mitre), 1 malware, 2 others

Description

A new malicious campaign has been discovered targeting the Python Package Index () by exploiting the Pickle file format in models. Three malicious packages posing as an Alibaba Labs SDK were detected, containing payloads hidden inside models. The packages exfiltrate information about infected machines and .gitconfig file contents. This attack demonstrates the evolving threat landscape in and , particularly in the software supply chain. The campaign likely targeted developers in China and highlights the need for improved security measures and tools to detect malicious functionality in ML models.

External references