ultralyticsPYSEC-2024-154
A number of releases of ultralytics contained malicious crypto miner software.
High8.6Published Dec 10, 2024 · updated Jun 28, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| ultralytics PyPI | >= 8.3.41, < 8.3.47 | 8.3.47 |
Details and references
Ultralytics has identified a supply chain attack affecting affecting multiple versions of the ultralytics package. The compromised versions contained unauthorized code that downloaded and executed cryptocurrency mining software when instantiating YOLO models. This code was injected into the PyPI release artifacts and was not present in the public GitHub repository.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
- Severity from
- the CVSS score
- inspector.pypi.io/project/ultralytics/8.3.41/packages/d0/99/13d92174aa6a470d348a95e31164769f2cdf77838ea3c3e3fd476285777d/ultralytics-8.3.41-py3-none-any.whl/ultralytics/utils/downloads.py#line.284
- github.com/ultralytics/ultralytics/pull/18020#issuecomment-2525180194
- github.com/ultralytics/ultralytics/issues/18027
- github.com/ultralytics/ultralytics/pull/18052
- github.com/ultralytics/ultralytics/pull/18111
- github.com/ultralytics/ultralytics/releases/tag/v8.3.48
- blog.yossarian.net/2024/12/06/zizmor-ultralytics-injection