logo

Ultralytics AI model hijacked to infect thousands with cryptominer

ID: c0cd1aa2-642a-5597-8c33-9d4972e9a3a1

STIX ID: report--c0cd1aa2-642a-5597-8c33-9d4972e9a3a1

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2024-12-06

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

Ultralytics YOLO packages published to PyPI (versions 8.3.41 and 8.3.42, with subsequent trojanized versions reported) were compromised via malicious code injection in pull requests, causing installation of an XMRig cryptocurrency miner at /tmp/ultralytics_runner connecting to connect.consrensys.com:8080; the malicious releases were pulled, a clean 8.3.43 was released, and the vendor is auditing the build environment while users are advised to scan affected systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.