Ultralytics AI Library Hacked via GitHub for Cryptomining | Wiz Blog
A supply chain attack on Ultralytics exploited GitHub Actions to inject malicious PyPI packages. Discover how it unfolded and the steps to mitigate the risk.
Security researchers have identified a supply chain attack targeting deployment versions of the Ultralytics Python package. The compromised versions, 8.3.41 and 8.3.42 , contain malicious code that executes unauthorized cryptocurrency mining software ( XMRig ) on affected machines. This compromise was limited to the PyPI-hosted versions of the package, and local or earlier versions remain unaffected. The malicious versions have since been removed from PyPI to prevent further exploitation. Ultralytics is a popular AI image prediction library with over 33k stars on GitHub and a dependency for ma
Explore this link on the map →saved by
related reading
- uv: An extremely Fast Python Package Manager :: Jane Streetjanestreet.com
- Security incident disclosure — July 2026huggingface.co
- Snyk on X: "@karpathy The LiteLLM dependency incident didn't "just happen" though. This is part of a larger campaign LiteLLM already extends to supply chain security fallout for other projects: https://t.co/7bL3kNHP15" / Xx.com
- Project Glasswing: Securing critical software for the AI era \ Anthropicanthropic.com
- Mythos finds a curl vulnerability | daniel.haxx.sedaniel.haxx.se
- Dependency Confusion: How I Hacked Into Apple, Microsoft and Dozens of Other Companies | by Alex Birsan | Mediummedium.com
- GitHub RCE Vulnerability: CVE-2026-3854 Breakdown | Wiz Blogwiz.io
- What I learned this week - Can distillation be stopped, Mythos and the cybersecurity equilibrium, Pipeline RLdwarkesh.com
- State of DevSecOps | Datadogdatadoghq.com
- 2312.06942arxiv.org
- GitHub - ourzora/v3 · GitHubgithub.com
- The Myth of unsafe Open Source AIflorianbrand.com