Loading...
Loading...
Browse all stories on DeepNewz
VisitPrimary method of compromise for future Python package breaches by June 30, 2025?
Malicious code injection • 25%
Credential theft • 25%
Dependency confusion • 25%
Other methods • 25%
Security research publications and news articles
Ultralytics AI Library and 'aiocpa' Python Package Compromised for Cryptocurrency Mining
Dec 7, 2024, 09:51 AM
Two versions of the popular Python AI library, Ultralytics, specifically versions 8.3.41 and 8.3.42, have been compromised to deliver cryptocurrency miners to users. The compromised packages, which include the home of yolov8 and yolo11, were found on the Python Package Index (PyPI). This breach has potentially affected thousands of users, including those using ComfyUI through the custom node ComfyUI-Impact-Pack. The incident has raised concerns over software supply chain security in the AI and machine learning community. Additionally, another Python package, 'aiocpa', was exposed as a cryptocurrency infostealer.
View original story
Removal of 'aiocpa' • 25%
Security Policy Update • 25%
No Action Taken • 25%
Other Measures • 25%
Bypassing user consent • 25%
Terminal redirection • 25%
Gatekeeper bypass • 25%
Other method • 25%
Phishing attacks • 25%
Direct server exploitation • 25%
Malware distribution • 25%
Other • 25%
Yes • 50%
No • 50%
Phishing • 25%
Direct network attack • 25%
Malware installation • 25%
Other • 25%
Kernel Rootkit • 25%
SSDT Hook • 25%
Infinityhook • 25%
Other • 25%
Disabling CUPS • 25%
Applying a security patch • 25%
Network segmentation • 25%
Other • 25%
Smart contract vulnerability • 25%
Oracle manipulation • 25%
Admin key compromise • 25%
Other • 25%
Yes • 50%
No • 50%
No major response • 25%
Increased security audits • 25%
Adoption of alternative libraries • 25%
Formation of a security consortium • 25%