CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Ultralytics AI Library Hacked via GitHub for Cryptomining

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 1517

As cited

Copy frozen at (site build).

threat intel

Ultralytics AI Library Hacked via GitHub for Cryptomining

Ultralytics, a popular AI library, was compromised through a supply chain attack that leveraged GitHub Actions to inject malicious packages into PyPI. The attacker used the compromised repository to distribute code for cryptomining purposes. Users who installed affected versions received malware designed to commandeer system resources.

Why it matters: Developers and organizations using Ultralytics for AI/ML workloads should audit installed versions immediately and check for unusual system activity or resource consumption indicating cryptomining activity.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Ultralytics AI Library Hacked via GitHub for Cryptomining

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Ultralytics AI Library Hacked via GitHub for Cryptomining

Attackers compromised Ultralytics' GitHub Actions workflow to push malicious versions of the library to PyPI. The tainted packages executed cryptomining code when installed by unsuspecting users. Maintainers have since revoked the compromised credentials and advised users to reinstall clean releases.

Why it matters: Developers and organizations that use Ultralytics or its PyPI packages are exposed to cryptomining malware and should verify package integrity and review their CI/CD configurations.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Ultralytics AI Library Hacked via GitHub for Cryptomining

Attackers compromised Ultralytics' GitHub Actions workflow to push malicious versions of the library to PyPI. The tainted packages executed cryptomining code when installed by unsuspecting users. Maintainers have since revoked the compromised credentials and advised users to reinstall clean releases.

Why it matters: Developers and organizations that use Ultralytics or its PyPI packages are exposed to cryptomining malware and should verify package integrity and review their CI/CD configurations.

VendorsGitHub
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary