Popular AI Library Ultralytics YOLO11 Compromised in Supply Chain Attack

3 Sources

Ultralytics YOLO11, a widely-used AI model for computer vision, was hacked to deliver cryptocurrency mining malware through its Python package, affecting thousands of users and highlighting the vulnerability of AI supply chains.

News article

Supply Chain Attack Targets Popular AI Library

Ultralytics YOLO11, a widely-used open-source AI model for computer vision and object detection, fell victim to a sophisticated supply chain attack. The compromise affected versions 8.3.41 and 8.3.42 of the library, which were uploaded to the Python Package Index (PyPI), one of the world's largest Python package repositories 1.

Impact and Scope of the Attack

The attack's impact was significant due to YOLO11's popularity. The library boasts over 30,000 stars on GitHub, has been forked more than 6,000 times, and sees hundreds of thousands of downloads daily 1. Users who updated to the compromised versions, either directly or through dependencies like SwarmUI and ComfyUI, inadvertently installed a cryptocurrency miner on their devices 2.

Malware Details and Functionality

The malware deployed was XMRig, a popular cryptojacker known for mining Monero (XMR), a privacy-oriented cryptocurrency that is difficult to trace 1. When installed, the compromised library would launch the XMRig Miner, connecting to a mining pool at "connect.consrensys[.]com:8080" 2.

Attack Vector and Sophistication

The attack exploited a vulnerability in the Ultralytics build environment. According to ReversingLabs researcher Karlo Zanki, the intrusion was achieved through a "known GitHub Actions Script Injection" vulnerability 3. This allowed the attacker to insert unauthorized modifications after the code review step, creating a discrepancy between the source code on GitHub and the package published on PyPI.

Response and Mitigation

Ultralytics founder and CEO Glenn Jocher confirmed the attack and stated that the compromised versions were immediately removed from PyPI. A new version, 8.3.43, was released to address the security issue 2. The company is conducting a full security audit and implementing additional safeguards to prevent similar incidents in the future.

Ongoing Concerns and Recommendations

Despite the initial response, there were reports of newer versions (8.3.45 and 8.3.46) also being "trojanized" 1. Users are advised to update to the latest clean version and perform a full system scan out of an abundance of caution. The incident highlights the potential risks in the AI supply chain, as more aggressive malware like backdoors or remote access trojans (RATs) could have been deployed instead of a cryptocurrency miner 3.

Explore today's top stories

Google Unveils Pixel 10 Series: AI-Powered Features and Camera Upgrades Take Center Stage

Google has launched its new Pixel 10 series, featuring improved AI capabilities, camera upgrades, and the new Tensor G5 chip. The lineup includes the Pixel 10, Pixel 10 Pro, and Pixel 10 Pro XL, with prices starting at $799.

Ars Technica logoTechCrunch logoCNET logo

60 Sources

Technology

14 hrs ago

Google Unveils Pixel 10 Series: AI-Powered Features and

Google Unveils AI-Powered Pixel 10 Smartphones with Advanced Gemini Features

Google launches its new Pixel 10 smartphone series, showcasing advanced AI capabilities powered by Gemini, aiming to compete with Apple in the premium handset market.

Bloomberg Business logoThe Register logoReuters logo

22 Sources

Technology

14 hrs ago

Google Unveils AI-Powered Pixel 10 Smartphones with

NASA and IBM Unveil Surya: An AI Model to Predict Solar Flares and Space Weather

NASA and IBM have developed Surya, an open-source AI model that can predict solar flares and space weather with improved accuracy, potentially helping to protect Earth's infrastructure from solar storm damage.

New Scientist logoengadget logoGizmodo logo

6 Sources

Technology

22 hrs ago

NASA and IBM Unveil Surya: An AI Model to Predict Solar

Google Unveils Pixel Watch 4: A Leap Forward in AI-Powered Wearables

Google's latest smartwatch, the Pixel Watch 4, introduces significant upgrades including a curved display, AI-powered features, and satellite communication capabilities, positioning it as a strong competitor in the smartwatch market.

TechCrunch logoCNET logoZDNet logo

18 Sources

Technology

13 hrs ago

Google Unveils Pixel Watch 4: A Leap Forward in AI-Powered

FieldAI Secures $405M Funding to Revolutionize Robot Intelligence with Physics-Based AI Models

FieldAI, a robotics startup, has raised $405 million to develop "foundational embodied AI models" for various robot types. The company's innovative approach integrates physics principles into AI, enabling safer and more adaptable robot operations across diverse environments.

TechCrunch logoReuters logoGeekWire logo

7 Sources

Technology

14 hrs ago

FieldAI Secures $405M Funding to Revolutionize Robot
TheOutpost.ai

Your Daily Dose of Curated AI News

Don’t drown in AI news. We cut through the noise - filtering, ranking and summarizing the most important AI news, breakthroughs and research daily. Spend less time searching for the latest in AI and get straight to action.

© 2025 Triveous Technologies Private Limited
Instagram logo
LinkedIn logo