Compromised ultralytics PyPI package delivers crypto coinminer
ID: dee5aed6-72de-5d3f-8bbb-b66151e5f97c
STIX ID: report--dee5aed6-72de-5d3f-8bbb-b66151e5f97c
Feed Name: ReversingLabs Blog
On Dec 4 a malicious 8.3.41 release of the popular ultralytics Python package was published to GitHub and PyPI after attackers exploited a known GitHub Actions script-injection vulnerability in the project's build pipeline; the injected code downloaded an XMRig coinminer and subsequent malicious releases were likely published using a stolen PyPI API token, affecting multiple versions and posing risk to the package's large user base (≈60M downloads), though a clean 8.3.43 release was later published.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
