Model Namespace Reuse: An AI Supply-Chain Attack Exploiting Model Name Trust
ID: afc5dc68-00aa-56cc-aa81-6aa47ae3bcb8
STIX ID: report--afc5dc68-00aa-56cc-aa81-6aa47ae3bcb8
Feed Name: Palo Alto Networks Unit 42
Palo Alto Networks Unit 42 describes a supply-chain vulnerability—"Model Namespace Reuse"—where abandoned or transferred Hugging Face Author/ModelName namespaces can be re-registered by attackers to replace trusted models, enabling malicious models to be deployed and resulting in remote code execution on platforms such as Google Vertex AI and Azure AI Foundry; the authors demonstrated reverse-shell execution, found thousands of affected open-source references, notified vendors (who have begun mitigations), and recommend version pinning, cloning models to trusted storage, and scanning model references.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
