Close Menu
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
What's Hot

Kraken Brings Regulated Perpetual Futures Onshore to US Users

June 16, 2026

Is California Reaching Critical Mass?

June 16, 2026

India’s NHRC Raises Alarm Over Digital Arrest Scams

June 16, 2026
Facebook X (Twitter) Instagram
Recession Profit AlertsRecession Profit Alerts
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
Recession Profit AlertsRecession Profit Alerts
Home»Security»Compromised AI Library Delivers Cryptocurrency Miner via PyPI
Compromised AI Library Delivers Cryptocurrency Miner via PyPI
Security

Compromised AI Library Delivers Cryptocurrency Miner via PyPI

February 25, 2026No Comments2 Mins Read

A compromised version of the popular ultralytics AI library has been found to deliver a cryptocurrency mining payload.

ReversingLabs researchers traced the issue to a breach of the library’s build environment, which was exploited through a known GitHub Actions script injection vulnerability.

On December 4, version 8.3.41 of ultralytics was published on the Python Package Index (PyPI). This version contained malicious code that downloaded the XMRig coin miner. The attackers used a sophisticated technique to inject malicious payloads into the repository, bypassing code reviews.

“Unlike the recent compromise of a trusted npm package @solana/web3.js […], which also had a similar impact radius but was caused by a compromise of one of the maintainer accounts, in this case, intrusion into the build environment was achieved by a more sophisticated vector, by exploiting a known GitHub Actions Script Injection that was previously reported by the security researcher Adnan Khan,” ReversingLabs explained.

Specifically, the attackers crafted pull requests with code embedded in branch titles, allowing them to achieve arbitrary code execution.

The breach had the potential to impact a vast user base, as ultralytics has over 30,000 stars on GitHub and nearly 60 million downloads on PyPI. The problem was exacerbated when a follow-up version, 8.3.42, was released to address the issue also carried the same malicious code. A clean version, 8.3.43, was finally made available later that day.

While the malicious code primarily deployed a cryptocurrency miner, researchers noted that the same vector could have been used to distribute more harmful malware, such as backdoors or remote access Trojans. The compromised code specifically targeted downloads.py and model.py, with functionality tailored to evaluate system configurations and deliver platform-specific payloads.

See also  Miner Weekly: $33B in Bonds Is Fueling the AI Megawatt Arms Race

Read more on software supply chain security risks: CISA Urges Improvements in US Software Supply Chain Transparency

The attack was linked to a GitHub account named openimbot, which had a suspicious activity pattern suggesting a possible account takeover. The attackers’ methodology involved embedding payload code in branch names, enabling backdoor access to the environment through crafted pull requests.

Source link

compromised cryptocurrency Delivers Library miner PyPI

Related Posts

India’s NHRC Raises Alarm Over Digital Arrest Scams

June 16, 2026

Rokarolla Trojan Combines Banking Fraud With Device Surveillance

June 16, 2026

Pyra to Cease Operations Following Drift Hack, Launches Fund Withdrawal Portal

June 16, 2026

Oklahoma Raises Alarm Over Fake Crypto Returns

June 16, 2026
Top Posts

Cango Posts $261.1M Q1 Loss as Bitcoin Price Slump Hits Mining Operations

June 1, 2026

Aave Founder Says V4 Spokes Will Drive Liquidity, Growth, and Monetization

June 16, 2026

AAVE Price Prediction: Recovery Toward $157-162 Target Despite Technical Weakness

February 3, 2026

Type above and press Enter to search. Press Esc to cancel.