Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

Solana adds $378M in tokenized T-bills – Is Ethereum losing ground?

August 16, 2026

Ripple to Attend Major White House Meeting

August 16, 2026

SurancePlus raise was 95% Oxbridge-funded

August 16, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»Compromised AI Library Delivers Cryptocurrency Miner via PyPI
Compromised AI Library Delivers Cryptocurrency Miner via PyPI
Security and Privacy

Compromised AI Library Delivers Cryptocurrency Miner via PyPI

December 9, 20241 Comment2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

A compromised version of the popular ultralytics AI library has been found to deliver a cryptocurrency mining payload.

ReversingLabs researchers traced the issue to a breach of the library’s build environment, which was exploited through a known GitHub Actions script injection vulnerability.

On December 4, version 8.3.41 of ultralytics was published on the Python Package Index (PyPI). This version contained malicious code that downloaded the XMRig coin miner. The attackers used a sophisticated technique to inject malicious payloads into the repository, bypassing code reviews.

“Unlike the recent compromise of a trusted npm package @solana/web3.js […], which also had a similar impact radius but was caused by a compromise of one of the maintainer accounts, in this case, intrusion into the build environment was achieved by a more sophisticated vector, by exploiting a known GitHub Actions Script Injection that was previously reported by the security researcher Adnan Khan,” ReversingLabs explained.

Specifically, the attackers crafted pull requests with code embedded in branch titles, allowing them to achieve arbitrary code execution.

The breach had the potential to impact a vast user base, as ultralytics has over 30,000 stars on GitHub and nearly 60 million downloads on PyPI. The problem was exacerbated when a follow-up version, 8.3.42, was released to address the issue also carried the same malicious code. A clean version, 8.3.43, was finally made available later that day.

While the malicious code primarily deployed a cryptocurrency miner, researchers noted that the same vector could have been used to distribute more harmful malware, such as backdoors or remote access Trojans. The compromised code specifically targeted downloads.py and model.py, with functionality tailored to evaluate system configurations and deliver platform-specific payloads.

See also  Scammers Bank on Cryptocurrency with Fake Apps

Read more on software supply chain security risks: CISA Urges Improvements in US Software Supply Chain Transparency

The attack was linked to a GitHub account named openimbot, which had a suspicious activity pattern suggesting a possible account takeover. The attackers’ methodology involved embedding payload code in branch names, enabling backdoor access to the environment through crafted pull requests.

Source link

Compromised Cryptocurrency delivers library Miner PyPI
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Vadzo Imaging Positions the IMX715 GigE Camera for Outdoor Vision: Innova-715CRS Delivers ONVIF-Compliant Ultra-Low Light and PTZ Long Range Capability

August 15, 2026

French Tax Agency Admits Data Breach as Hacker Steals 678k Records

August 15, 2026

Bitcoin miner stocks rally in 2026 – How AI infrastructure reshaped BTC’s outlook

August 14, 2026

Trezor Shipping Provider Exposes 13,689 Crypto Customers to Scams

August 13, 2026
View 1 Comment

1 Comment

  1. Blue Tech on December 10, 2024 6:17 am

    Blue Techker There is definately a lot to find out about this subject. I like all the points you made

    Reply
Leave A Reply Cancel Reply

Top Posts

Binance.US Lost As Judge Rejects Its Accusations Of SEC Misleading Statements

June 27, 2023

Goldfinch wind-down raises a hard question

June 24, 2026

Filecoin: Why FIL’s breakdown below $0.80 signals a major shift

June 7, 2026

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Solana adds $378M in tokenized T-bills – Is Ethereum losing ground?

August 16, 2026

Ripple to Attend Major White House Meeting

August 16, 2026

SurancePlus raise was 95% Oxbridge-funded

August 16, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$62,766.00-0.20%
  • ethereumEthereum(ETH)$1,872.66-0.40%
  • tetherTether(USDT)$1.000.00%
  • binancecoinBNB(BNB)$601.41-1.00%
  • usd-coinUSDC(USDC)$1.000.00%
  • rippleXRP(XRP)$0.99-0.80%
  • solanaSolana(SOL)$74.35-1.50%
  • tronTRON(TRX)$0.3309960.00%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.00-0.50%
  • HyperliquidHyperliquid(HYPE)$57.160.70%