logo

Open Source AI Models: Perfect Storm for Malicious Code, Vulnerabilities

ID: 3ee0c85f-fb03-5393-9796-45d85600cd2c

STIX ID: report--3ee0c85f-fb03-5393-9796-45d85600cd2c

Feed Name: Dark Reading

Threat Score
55/100

Date Published: 2025-02-14

Date Updated: 2026-04-21

Author: Robert Lemos, Contributing Writer

...
...

Researchers found proof-of-concept malicious AI models hosted on public repositories (Hugging Face and others) that bypass automated security checks by abusing the insecure Python Pickle format and using evasion techniques (dubbed "NullifAI"); the report warns that executable model/data files create supply-chain risks, recommends safer formats like Safetensors, and urges organizations to treat open-source models like any other third-party dependency with attention to licensing, alignment, and operational security.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.