logo

Malicious ML models discovered on Hugging Face platform

ID: 79e21a83-8949-51c5-b309-700e90c81e72

STIX ID: report--79e21a83-8949-51c5-b309-700e90c81e72

Feed Name: ReversingLabs Blog

Threat Score
70/100

Date Published: 2025-02-06

Date Updated: 2026-04-29

Author: [email protected] (Karlo Zanki)

...
...

ReversingLabs discovered malicious ML models on Hugging Face that abused Python Pickle serialization in PyTorch model archives to execute arbitrary code during deserialization (including a reverse shell to 107.173.7.141). The research shows how compression and intentionally broken Pickle streams allowed the payload to run while evading Picklescan detection, provides IOCs and detection guidance, and notes Hugging Face removed the malicious models and updated scanning tooling.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.