flâneur — a map of the web's best reading

Ultralytics AI Library Hacked via GitHub for Cryptomining | Wiz Blog

wiz.io · 851 words · saved by 1 readers

A supply chain attack on Ultralytics exploited GitHub Actions to inject malicious PyPI packages. Discover how it unfolded and the steps to mitigate the risk.

Security researchers have identified a supply chain attack targeting deployment versions of the Ultralytics Python package. The compromised versions, 8.3.41 and 8.3.42 , contain malicious code that executes unauthorized cryptocurrency mining software ( XMRig ) on affected machines. This compromise was limited to the PyPI-hosted versions of the package, and local or earlier versions remain unaffected. The malicious versions have since been removed from PyPI to prevent further exploitation. Ultralytics is a popular AI image prediction library with over 33k stars on GitHub and a dependency for ma

Explore this link on the map →

saved by

related reading