Malicious AI Models Bypass Picklescan Detection (Campaign)
ID: c67bf822-e61a-5a0b-a784-bf58ba288f58
STIX ID: report--c67bf822-e61a-5a0b-a784-bf58ba288f58
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2025-02-09
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
Malicious PyTorch models uploaded to Hugging Face used a Pickle serialization attack (termed nullifAI) that embedded a reverse shell payload at the start of the Pickle stream and were compressed with 7z to evade Picklescan; the payload attempted to connect to a hardcoded IP. Hugging Face removed the models within 24 hours after disclosure and Picklescan’s detection capabilities were improved.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
