logo

Ultralytics AI Library Hacked via GitHub for Cryptomining

ID: c8440030-5420-511c-b51e-27156ab9fa5b

STIX ID: report--c8440030-5420-511c-b51e-27156ab9fa5b

Feed Name: Wiz Blog

Threat Score
80/100

Date Published: 2024-12-09

Date Updated: 2026-05-01

...
...

Security researchers found that PyPI versions 8.3.41 and 8.3.42 of the Ultralytics Python package were backdoored via a GitHub Actions CI/CD vulnerability that allowed attackers to inject an XMRig cryptominer into release artifacts; the malicious versions were published to PyPI (affecting downstream projects like ComfyUI), subsequently removed, and users are advised to uninstall the affected packages and remediate any infected systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.