logo

Malicious AI Models Bypass Picklescan Detection (Campaign)

ID: c67bf822-e61a-5a0b-a784-bf58ba288f58

STIX ID: report--c67bf822-e61a-5a0b-a784-bf58ba288f58

Feed Name: Wiz Cloud Threat Landscape

Threat Score
70/100

Date Published: 2025-02-09

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Malicious PyTorch models uploaded to Hugging Face used a Pickle serialization attack (termed nullifAI) that embedded a reverse shell payload at the start of the Pickle stream and were compressed with 7z to evade Picklescan; the payload attempted to connect to a hardcoded IP. Hugging Face removed the models within 24 hours after disclosure and Picklescan’s detection capabilities were improved.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.