Ultralytics AI Library Hacked via GitHub for Cryptomining
wiz.io | incident | #ai-security | #supply-chain | #github-actions | #pypi | #incident | #cryptomining | #ultralytics
Summary
Wiz details how attackers injected the XMRig cryptominer into Ultralytics PyPI releases 8.3.41/8.3.42 by exploiting GitHub Actions branch-name handling, a rare external compromise reaching PyPI.
- Published
- Collected
Skip to content