Skip to content
ultralyticsPYSEC-2024-154

A number of releases of ultralytics contained malicious crypto miner software.

High8.6Published Dec 10, 2024 · updated Jun 28, 2026

Source advisory

Affected versions

PackageAffectedFixed in
ultralytics
PyPI
>= 8.3.41, < 8.3.478.3.47
Details and references

Ultralytics has identified a supply chain attack affecting affecting multiple versions of the ultralytics package. The compromised versions contained unauthorized code that downloaded and executed cryptocurrency mining software when instantiating YOLO models. This code was injected into the PyPI release artifacts and was not present in the public GitHub repository.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
Severity from
the CVSS score

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.