Ultralytics compromise (Incident)
ID: a78288ac-a1a1-572f-8e4a-595e1a9ec58a
STIX ID: report--a78288ac-a1a1-572f-8e4a-595e1a9ec58a
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2024-12-05
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
A supply-chain attack was discovered targeting the Ultralytics Python package: PyPI-hosted versions 8.3.41 and 8.3.42 included malicious code that installed and ran the XMRig cryptocurrency miner. The attacker leveraged a CI/CD vector—manipulating GitHub Actions via branch names in pull requests—to execute arbitrary code and bundle the miner; a follow-up "mitigation" release was also compromised, increasing exposure for users who updated.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
