Malicious ML models discovered on Hugging Face platform
ID: 79e21a83-8949-51c5-b309-700e90c81e72
STIX ID: report--79e21a83-8949-51c5-b309-700e90c81e72
Feed Name: ReversingLabs Blog
Threat Score
ReversingLabs discovered malicious ML models on Hugging Face that abused Python Pickle serialization in PyTorch model archives to execute arbitrary code during deserialization (including a reverse shell to 107.173.7.141). The research shows how compression and intentionally broken Pickle streams allowed the payload to run while evading Picklescan detection, provides IOCs and detection guidance, and notes Hugging Face removed the malicious models and updated scanning tooling.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
