Ultralytics AI Library Hacked via GitHub for Cryptomining
ID: c8440030-5420-511c-b51e-27156ab9fa5b
STIX ID: report--c8440030-5420-511c-b51e-27156ab9fa5b
Feed Name: Wiz Blog
Threat Score
Security researchers found that PyPI versions 8.3.41 and 8.3.42 of the Ultralytics Python package were backdoored via a GitHub Actions CI/CD vulnerability that allowed attackers to inject an XMRig cryptominer into release artifacts; the malicious versions were published to PyPI (affecting downstream projects like ComfyUI), subsequently removed, and users are advised to uninstall the affected packages and remediate any infected systems.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
