Ultralytics Supply-Chain Attack
ID: 1e8a5bca-9722-5f45-87bf-16b0acfb4374
STIX ID: report--1e8a5bca-9722-5f45-87bf-16b0acfb4374
Feed Name: Schneier on Security
Threat Score
A malicious version (8.3.41) of the Ultralytics Python package was published to PyPI on December 4 containing downloader code that delivered the XMRig coinminer; the attackers compromised the project's build environment via a known GitHub Actions script injection. The report links to detailed analyses and PyPI guidance on mitigations such as reviewing API token usage and GitHub Trusted Publisher/Environment configurations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
