As cited
Copy frozen at (site build).
threat intel
Ultralytics AI Library Hacked via GitHub for Cryptomining
Ultralytics, a popular AI library, was compromised through a supply chain attack that leveraged GitHub Actions to inject malicious packages into PyPI. The attacker used the compromised repository to distribute code for cryptomining purposes. Users who installed affected versions received malware designed to commandeer system resources.
Why it matters: Developers and organizations using Ultralytics for AI/ML workloads should audit installed versions immediately and check for unusual system activity or resource consumption indicating cryptomining activity.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Ultralytics AI Library Hacked via GitHub for Cryptomining
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Ultralytics AI Library Hacked via GitHub for Cryptomining
Attackers compromised Ultralytics' GitHub Actions workflow to push malicious versions of the library to PyPI. The tainted packages executed cryptomining code when installed by unsuspecting users. Maintainers have since revoked the compromised credentials and advised users to reinstall clean releases.
Why it matters: Developers and organizations that use Ultralytics or its PyPI packages are exposed to cryptomining malware and should verify package integrity and review their CI/CD configurations.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Ultralytics AI Library Hacked via GitHub for Cryptomining
Attackers compromised Ultralytics' GitHub Actions workflow to push malicious versions of the library to PyPI. The tainted packages executed cryptomining code when installed by unsuspecting users. Maintainers have since revoked the compromised credentials and advised users to reinstall clean releases.
Why it matters: Developers and organizations that use Ultralytics or its PyPI packages are exposed to cryptomining malware and should verify package integrity and review their CI/CD configurations.
- Source published
- First seen by Cybersecurity Tracker