logo

Malicious attack method on hosted ML models now targets PyPI

ID: 3dc0a449-4d26-55bc-b17a-3c5945fda352

STIX ID: report--3dc0a449-4d26-55bc-b17a-3c5945fda352

Feed Name: ReversingLabs Blog

Threat Score
70/100

Date Published: 2025-05-23

Date Updated: 2026-04-29

Author: [email protected] (Karlo Zanki)

...
...

ReversingLabs researchers discovered a short-lived PyPI supply-chain campaign delivering malicious Python packages that load Pickle-formatted PyTorch models which execute an infostealer at install time; the payload gathers system and .gitconfig data (likely targeting developers in China), was downloaded ~1,600 times across three packages, and highlights gaps in traditional security tooling for detecting executable behavior in ML model files.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.