logo

Compromised ultralytics PyPI package delivers crypto coinminer

ID: dee5aed6-72de-5d3f-8bbb-b66151e5f97c

STIX ID: report--dee5aed6-72de-5d3f-8bbb-b66151e5f97c

Feed Name: ReversingLabs Blog

Threat Score
85/100

Date Published: 2024-12-09

Date Updated: 2026-04-29

Author: [email protected] (Karlo Zanki)

...
...

On Dec 4 a malicious 8.3.41 release of the popular ultralytics Python package was published to GitHub and PyPI after attackers exploited a known GitHub Actions script-injection vulnerability in the project's build pipeline; the injected code downloaded an XMRig coinminer and subsequent malicious releases were likely published using a stolen PyPI API token, affecting multiple versions and posing risk to the package's large user base (≈60M downloads), though a clean 8.3.43 release was later published.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.