#Ultralytics
absolutely incredible attack vector
December 6, 2024 at 3:27 AM
(someone used a carefully crafted branch name to inject a crypto miner into a popular Python package: github.com/ultralytics/...)
Discrepancy between what's in GitHub and what's been published to PyPI for v8.3.41 · Issue #18027 · ultralytics/ultralytics
Bug Code in the published wheel 8.3.41 is not what's in GitHub and appears to invoke mining. Users of ultralytics who install 8.3.41 will unknowingly execute an xmrig miner. Examining the file util...
github.com
December 6, 2024 at 3:28 AM
in computer news: lol, lmao

github.com/ultralytics/...

it looks like github actions got tricked into running bash through a malicious branch name

which was used to ship mining malware inside python packages

incredible
Discrepancy between what's in GitHub and what's been published to PyPI for v8.3.41 · Issue #18027 · ultralytics/ultralytics
Bug Code in the published wheel 8.3.41 is not what's in GitHub and appears to invoke mining. Users of ultralytics who install 8.3.41 will unknowingly execute an xmrig miner. Examining the file util...
github.com
December 6, 2024 at 2:04 PM
zizmor would have caught the Ultralytics workflow vulnerability https://blog.yossarian.net/2024/12/06/zizmor-ultralytics-injection #security #oss
December 6, 2024 at 5:40 PM
popular computer vision package ultralytics (home of yolov8 and yolo11) was compromised.

a crypto miner was injected into versions 8.3.41 and 8.3.42.

link: github.com/ultralytics/...
December 5, 2024 at 9:21 PM
Lets just be grateful that most supply chain attacks are crypto weenie attacks and nothing more serious

github.com/ultralytics/...

silver lining and all that
Discrepancy between what's in GitHub and what's been published to PyPI for v8.3.41 · Issue #18027 · ultralytics/ultralytics
Bug Code in the published wheel 8.3.41 is not what's in GitHub and appears to invoke mining. Users of ultralytics who install 8.3.41 will unknowingly execute an xmrig miner. Examining the file util...
github.com
December 7, 2024 at 8:36 AM
here `git pull origin ${{ github.head_ref || github.ref }}` github.com/ultralytics/...

I believe if they'd have used the github.com/actions/chec... instead it would not have had the issue
`ultralytics 8.3.43` PyPI publishing security fix (#18052) · ultralytics/ultralytics@68c63a7
Signed-off-by: Glenn Jocher <glenn.jocher@ultralytics.com> Signed-off-by: UltralyticsAssistant <web@ultralytics.com> Co-authored-by: UltralyticsAssistant <web@ultralytics.com>
github.com
December 6, 2024 at 9:27 AM
conclusions from today's live writeup of the ultralytics vulnerability:

blog.yossarian.net/2024/12/06/z...
December 6, 2024 at 9:37 PM
Last week the Python package "Ultralytics" suffered a supply-chain attack on its build and release process. This is a review of the attack from @pypi.org's perspective.

There's plenty of advice for how Python projects can increase their #security posture:

blog.pypi.org/posts/2024-1...
Supply-chain attack analysis: Ultralytics - The Python Package Index Blog
Analysis of a package targeted by a supply-chain attack to the build and release process
blog.pypi.org
December 11, 2024 at 3:22 PM
A threat actor has added a hidden cryptominer into the Python package of the Ultralytics AI toolkit

blog.yossarian.net/2024/12/06/z...
December 8, 2024 at 10:52 AM
There's a great analysis here by @yossarian.net : blog.yossarian.net/2024/12/06/z...
zizmor would have caught the Ultralytics workflow vulnerability
blog.yossarian.net
December 6, 2024 at 7:58 PM
Ultralytics YOLO version 8.3.41 has been compromised, and contains a crypto miner.
December 11, 2024 at 10:58 PM
Pytorch + Ultralytics + ROS2 Humble on a Nvidia Jetson Nano with no Docker!

Pixi, together with @condaforge and @RoboStack, makes this possible!

#ROS #nvidia #opencv
April 9, 2026 at 9:45 AM
Legitimate supply-chain attack affecting Python package "Ultralytics" abused multiple levels of GitHub Actions shell injection vulnerabilities in workflows to publish malware to PyPI.
December 6, 2024 at 6:12 AM
Ultralytics AI model hijacked to infect thousands with cryptominer
Ultralytics AI model hijacked to infect thousands with cryptominer
The popular Ultralytics YOLO11 AI model was compromised in a supply chain attack to deploy cryptominers on devices running versions 8.3.41 and 8.3.42 from the Python Package Index (PyPI)
www.bleepingcomputer.com
December 6, 2024 at 7:11 PM
Apparent supply chain attack on Ultralytics, a popular AI Python library. Threat actor managed to insert cryptojacking functionality into specific versions (which have since been removed from PyPI).
github.com/ultralytics/...
Discrepancy between what's in GitHub and what's been published to PyPI for v8.3.41 · Issue #18027 · ultralytics/ultralytics
Bug Code in the published wheel 8.3.41 is not what's in GitHub and appears to invoke mining. Users of ultralytics who install 8.3.41 will unknowingly execute an xmrig miner. Examining the file util...
github.com
December 5, 2024 at 2:53 PM
Ultralytics AI Library Compromised: Cryptocurrency Miner Found in PyPI Versions
Ultralytics AI Library Compromised: Cryptocurrency Miner Found in PyPI Versions
thehackernews.com
December 7, 2024 at 11:32 AM
Deep analysis on the Ultralytics workflow vulnerability blog.yossarian.net/2024/12/06/z...
zizmor would have caught the Ultralytics workflow vulnerability
blog.yossarian.net
December 6, 2024 at 9:35 PM
PyPI confirms no security flaws were exploited in the Ultralytics supply chain attack and the team is working on two new efforts to nudge developers towards more secure publishing configurations.

socket.dev/blog/pypi-on... #Python @pypi.org @python.org
PyPI on Ultralytics Breach: Poor CI/CD Practices to Blame, N...
PyPI confirms no security flaws were exploited in the Ultralytics supply chain attack and highlights improvements for safer package publishing.
socket.dev
December 14, 2024 at 12:26 AM
🚨 Ultralytics AI, with 60 million+ downloads, was compromised via GitHub Actions after hackers injected malicious code, turning the library into a #cryptomining tool.

Read: hackread.com/ultralytics-...

#CyberSecurity #Python #Crypto #Malware #AI
Ultralytics AI Library with 60M Downloads Compromised for Cryptomining
Follow us on Bluesky, Twitter (X) and Facebook at @Hackread
hackread.com
December 9, 2024 at 12:49 PM
Raspberry Pi - Article
"Run Ultralytics YOLO on Raspberry Pi with OpenVINO"...

www.raspberrypi.com/news/run-ult...

==========================
#librecanada #linux #opensource
Run Ultralytics YOLO on Raspberry Pi with OpenVINO - Raspberry Pi
A practical guide to deploying Ultralytics YOLO computer vision models at the edge with Raspberry Pi and OpenVINO.
www.raspberrypi.com
July 17, 2026 at 11:53 AM
ultralytics v8.4.142 — Deep learning framework for object detection, segmentation, classification, pose estimation, and tracking using pre-trained YOLO models... https://kitploit.com/tools/github/ultralytics/ultralytics?utm_source=bluesky&utm_medium=social&utm_campaign=kitploit&utm_content=358963
September 10, 2026 at 5:57 PM
📦 ultralytics / ultralytics
⭐ 29,095 (+59)
🗒 Python

NEW - YOLOv8 🚀 in PyTorch > ONNX > OpenVINO > CoreML > TFLite
GitHub - ultralytics/ultralytics: NEW - YOLOv8 🚀 in PyTorch > ONNX > OpenVINO > CoreML > TFLite
NEW - YOLOv8 🚀 in PyTorch > ONNX > OpenVINO > CoreML > TFLite - ultralytics/ultralytics
github.com
October 1, 2024 at 12:01 PM