logo

Ultralytics Supply-Chain Attack

ID: 1e8a5bca-9722-5f45-87bf-16b0acfb4374

STIX ID: report--1e8a5bca-9722-5f45-87bf-16b0acfb4374

Feed Name: Schneier on Security

Threat Score
85/100

Date Published: 2024-12-13

Date Updated: 2026-04-19

Author: Bruce Schneier

...
...

A malicious version (8.3.41) of the Ultralytics Python package was published to PyPI on December 4 containing downloader code that delivered the XMRig coinminer; the attackers compromised the project's build environment via a known GitHub Actions script injection. The report links to detailed analyses and PyPI guidance on mitigations such as reviewing API token usage and GitHub Trusted Publisher/Environment configurations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.