Malicious AI models on Hugging Face backdoor users’ machines
ID: db0828c2-4f57-501e-ac19-2c0d99b1ae57
STIX ID: report--db0828c2-4f57-501e-ac19-2c0d99b1ae57
Feed Name: Bleeping Computer
Threat Score
JFrog discovered approximately 100 malicious ML models on Hugging Face that embed harmful payloads (notably using Python pickle __reduce__ in PyTorch models) enabling arbitrary code execution and reverse shells to remote IPs; the findings indicate a meaningful risk of backdoors, data breaches, and espionage despite Hugging Face's scanning measures, and JFrog's honeypot captured connections but no commands.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
