techy @techy.detectionengineering.net · Dec 7

Ultralytics, a python package with close to 6.4 million downloads per month, was backdoored to run a cryptominer. Running theory from the reported GitHub issue is a GitHub action injection attack, but theres also evidence that the malicious code was published directly via PyPi and skipped CI/CD

10 likes 1 replies

?

Replies

techy · Dec 7

Quick guarddog scan found the offending code on one of the malicious versions. Unremarkably, its dropping cryptomining binaries for Linux and MacOS. An OSV entry for ultralytics malware still hasn't made it to the main osv database