logo

Malicious AI Models on Hugging Face Exploit Novel Attack Technique

ID: 48284175-b674-5302-9a11-c9d01fd18512

STIX ID: report--48284175-b674-5302-9a11-c9d01fd18512

Feed Name: Infosecurity Magazine (News)

Threat Score
35/100

Date Published: 2025-02-07

Date Updated: 2026-04-22

...
...

Reversing Labs found two malicious ML models on Hugging Face that used 7z-compressed PyTorch (Pickle) files to bypass the platform's Picklescan detection, demonstrating a novel technique for embedding malicious code in 'broken' Pickle streams; Hugging Face removed the models within 24 hours and updated Picklescan to detect threats in broken Pickle files.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.