Today > | 5 High | 10 Medium vulnerabilities   -   You can now download lists of IOCs here!

Compromised ultralytics PyPI package delivers crypto coinminer

Dec. 9, 2024, 11:31 a.m.

Description

A malicious version of the popular AI library ultralytics was published on PyPI, containing downloader code for the XMRig coinminer. The compromise was achieved by exploiting a known GitHub Actions script injection. Two versions, 8.3.41 and 8.3.42, were affected before a clean version 8.3.43 was released. The attack had potential to impact millions of users due to the package's popularity. The infection vector involved crafting malicious pull requests to gain backdoor access. The compromise was initiated from Hong Kong. The malicious code was inserted into downloads.py and model.py files, designed to download platform-specific payloads. While this incident focused on cryptocurrency mining, it could have been used to deploy more aggressive malware.

Date

Published: Dec. 7, 2024, 12:25 p.m.

Created: Dec. 7, 2024, 12:25 p.m.

Modified: Dec. 9, 2024, 11:31 a.m.

Attack Patterns

XMRig

T1195.001

T1027.001

T1102.002

T1564.001

T1059.001

T1571

T1564

T1082

T1105

T1083

T1102

T1027

T1195

T1059