Toutes les vulnérabilités
HIGHSupply chainexploited in the wild

SC-ULTRALYTICS-PYPI-2024

PyPI · ultralytics

Résumé

On December 4-5, 2024 the popular ultralytics YOLO Python package was compromised on PyPI (versions 8.3.41 and 8.3.42). An attacker abused a GitHub Actions script-injection flaw by opening draft pull requests whose branch names contained a malicious payload, then leveraged GitHub Actions cache poisoning to inject code into the trusted PyPI publishing workflow. The patched safe_download and safe_run functions downloaded and ran an XMRig Monero cryptominer on affected machines. The malicious versions were live for only a few hours each before removal; local and earlier versions were unaffected.

Références

Vulnérabilités liées

Tout Supply chain →