logo

Hugging Face platform continues to be plagued by vulnerable ‘pickles’

ID: 6d894c22-7090-5a62-8dc1-1d89ed5f92a8

STIX ID: report--6d894c22-7090-5a62-8dc1-1d89ed5f92a8

Feed Name: CyberScoop

Threat Score
50/100

Date Published: 2025-02-06

Date Updated: 2026-04-21

Author: djohnson

...
...

ReversingLabs identified two machine-learning models hosted on Hugging Face that used malicious Python pickle files to deploy web shells pointing to a hardcoded IP, evading the platform's Picklescan scanner by using alternative compression and broken-pickle techniques; the packages appeared to be proof-of-concept rather than widespread active exploitation, were removed after disclosure on Jan 20, and Picklescan received updates to better detect malicious or corrupted pickle payloads.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.