Ultralytics AI Library Hacked via GitHub for Cryptomining | Wiz Blog
A supply chain attack on Ultralytics exploited GitHub Actions to inject malicious PyPI packages. Discover how it unfolded and the steps to mitigate the risk.
Security researchers have identified a supply chain attack targeting deployment versions of the Ultralytics Python package. The compromised versions, 8.3.41 and 8.3.42 , contain malicious code that executes unauthorized cryptocurrency mining software ( XMRig ) on affected machines. This compromise was limited to the PyPI-hosted versions of the package, and local or earlier versions remain unaffected. The malicious versions have since been removed from PyPI to prevent further exploitation. Ultralytics is a popular AI image prediction library with over 33k stars on GitHub and a dependency for ma
saved by
related reading
- Countering misuse of AI: September 2026 / Anthropicanthropic.com
- Security incident disclosure — July 2026huggingface.co
- Snyk on X: "@karpathy The LiteLLM dependency incident didn't "just happen" though. This is part of a larger campaign LiteLLM already extends to supply chain security fallout for other projects: https://t.co/7bL3kNHP15" / Xx.com
- GitHub - w1b/aisi-mythos-inc-2026-07-28-01-recovered-pr: here's the evil malware Mythos made. idk... i think i could do better bro. shout out codex for slopping this out i didn't write a single line of anythinggithub.com
- OpenAI – Hugging Face Incident Technical Reportcdn.openai.com
- The Rise and Fall of Agent Civilizationsdwarkesh.com
- Incident Report: unsanctioned agent behaviour during cyber testing | AISI Workaisi.gov.uk
- 6a724858f7db25c81487016d_Security Incident INC-2026-07-28-01.pdfcdn.prod.website-files.com
- OpenAI agents carried out an undisclosed cyber-attack on RubyGemsrubyhack.ai
- Investigating three real-world incidents in our cybersecurity evaluations \ Anthropicanthropic.com
- Detecting and preventing distillation attacks \ Anthropicanthropic.com
- Mythos finds a curl vulnerability | daniel.haxx.sedaniel.haxx.se