Compromised ultralytics PyPI package delivers crypto coinminer
Dec. 9, 2024, 11:31 a.m.
Tags
External References
Description
A malicious version of the popular AI library ultralytics was published on PyPI, containing downloader code for the XMRig coinminer. The compromise was achieved by exploiting a known GitHub Actions script injection. Two versions, 8.3.41 and 8.3.42, were affected before a clean version 8.3.43 was released. The attack had potential to impact millions of users due to the package's popularity. The infection vector involved crafting malicious pull requests to gain backdoor access. The compromise was initiated from Hong Kong. The malicious code was inserted into downloads.py and model.py files, designed to download platform-specific payloads. While this incident focused on cryptocurrency mining, it could have been used to deploy more aggressive malware.
Date
Published: Dec. 7, 2024, 12:25 p.m.
Created: Dec. 7, 2024, 12:25 p.m.
Modified: Dec. 9, 2024, 11:31 a.m.
Attack Patterns
XMRig
T1195.001
T1027.001
T1102.002
T1564.001
T1059.001
T1571
T1564
T1082
T1105
T1083
T1102
T1027
T1195
T1059