Close Menu
  • Latest News
    • Bitcoin
    • Ethereum
    • Altcoins
    • Meme Coins
  • DeFi
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • Gaming
  • Legal
    • Taxes & Regulation
    • Adoption
  • Analysis
  • Learn
    • Education
    • Wallets and Exchanges
  • Tools
    • Market Overview
    • Converter
What's Hot

ONDO price rallies on 21Shares’ ETF filing and major exchange listing

July 23, 2025

Bank of England Considers Abandoning Digital Pound CBDC Project Amid Growing Opposition

July 23, 2025

Ethereum Price Prediction – $4,096 Breakout or Pullback to $3,525?

July 23, 2025
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
Facebook X (Twitter) Instagram
Buy Crypto NewsBuy Crypto News
  • Latest News
    1. Bitcoin
    2. Ethereum
    3. Altcoins
    4. Meme Coins
    5. View All

    Solana's SOL Could Hit $500 in This Bull Run, Says Analyst, as Upexi Boosts Holdings to 1.8M SOL

    July 23, 2025

    Asia Morning Briefing: The First AI vs BTC Environmental Impact Numbers are Here. And it Might Start a New Debate

    July 23, 2025

    Are Bitcoin Whales Dumping Their BTC?

    July 23, 2025

    Bitcoin Price Today Tests $116K Support – Is the Rally Still Alive?

    July 22, 2025

    Ethereum Price Prediction – $4,096 Breakout or Pullback to $3,525?

    July 23, 2025

    Inside why a $6 billion NFT market cap surge is fueling Ethereum’s Q3 bull case!

    July 23, 2025

    Accumulation of Major Bitcoin Investors and Whales Powering BTC Uptrend As Ethereum Witnesses Trend Reversal in Buyer Behavior: Glassnode

    July 23, 2025

    Ethereum and Cardano Price Prediction: Is $5K ETH and $5 ADA on Horizon?

    July 22, 2025

    These Two Bearish Scenarios Put Solana Price At $162 After Fakeout

    July 23, 2025

    Bitcoin faces profit-taking, but 4 reasons why BTC’s rally isn’t over yet!

    July 23, 2025

    Solana’s (SOL) Utility Token Skyrocketed, Here’s Why This New Audited AI Token Could Be Next To Reach The Charts

    July 23, 2025

    Venture Capital Firms Launch $360,000,000 Crypto Treasury Company Focused on Arthur Hayes-Backed Ethena (ENA)

    July 22, 2025

    Pepe, BMT, CAKE: Crypto Activity Heats Up

    March 18, 2025

    SHIB Burns Over Half a Billion Tokens, Price Surges Over 7%

    March 17, 2025

    DOGE Sees Massive User Growth: Active Addresses Up 400%

    March 15, 2025

    Shiba Inu (SHIB) Price Analysis: Bullish Hints, Bearish Trend

    March 15, 2025

    ONDO price rallies on 21Shares’ ETF filing and major exchange listing

    July 23, 2025

    Bank of England Considers Abandoning Digital Pound CBDC Project Amid Growing Opposition

    July 23, 2025

    Ethereum Price Prediction – $4,096 Breakout or Pullback to $3,525?

    July 23, 2025

    Solana's SOL Could Hit $500 in This Bull Run, Says Analyst, as Upexi Boosts Holdings to 1.8M SOL

    July 23, 2025
  • DeFi

    ONDO price rallies on 21Shares’ ETF filing and major exchange listing

    July 23, 2025

    Crypto acts like land, not tech, and that’s why it’s weird

    July 23, 2025

    Will Spark spike to $1?

    July 23, 2025

    Zebec crypto extends rally on Algorand integration into Zebec Cards and payroll ecosystem

    July 22, 2025

    Is Bitcoin at risk of correction as SpaceX wallet moves $152m in BTC after three years?

    July 22, 2025
  • Tech
    1. Blockchain
    2. Security and Privacy
    3. View All

    Bank of England Considers Abandoning Digital Pound CBDC Project Amid Growing Opposition

    July 23, 2025

    Ethereum Dominates DeFi, Solana, Bitcoin, BSC, Tron, and Others among Top 10 

    July 23, 2025

    Ken Griffin’s Citadel Urges SEC to Treat Tokenized Shares Like Traditional Stocks

    July 23, 2025

    Helios Blockchain Partners ZNS Connect to Launch Web3 Naming on Testnet

    July 23, 2025

    Accounting Firm Targeted by Malware Campaign Using New Crypter

    July 22, 2025

    Grok refuses to pick winner for Crypto Rover competition citing ZachXBT pump and dump evidence

    July 21, 2025

    XRP trading volume soars as new ATH attracts deepfake scam targeting investors

    July 18, 2025

    AI-Generated Lcryx Ransomware Discovered in Cryptomining Botnet

    July 18, 2025

    ONDO price rallies on 21Shares’ ETF filing and major exchange listing

    July 23, 2025

    Bank of England Considers Abandoning Digital Pound CBDC Project Amid Growing Opposition

    July 23, 2025

    Ethereum Price Prediction – $4,096 Breakout or Pullback to $3,525?

    July 23, 2025

    Solana's SOL Could Hit $500 in This Bull Run, Says Analyst, as Upexi Boosts Holdings to 1.8M SOL

    July 23, 2025
  • Web 3
    1. Web3 News
    2. Gaming
    3. View All

    Industrial Valves Market Top Companies Study – Emerson, Flowserve Corporation, Sclumberger Limited, Crane Co., Neles.

    July 23, 2025

    Introducing .DSci: A Domain for Decentralized Onchain Science

    July 23, 2025

    Global Security & Vulnerability Management Market to Surge to USD 9.34 Billion by 2034 Amid Escalating Cyber Threats

    July 23, 2025

    What Is an A Record? A Complete Guide to DNS A Records

    July 22, 2025

    Elderglade’s Cross-Chain Gaming Bridge is Live, Going Cross-Game and Cross-Chain with LINEUP Games Partnership

    July 23, 2025

    A $7.8M stealth CryptoPunks acquisition signals renewed whale interest in NFTs amid Ethereum’s rally and a resurgent market.

    July 22, 2025

    GaFin Partners with Play Off The Grid to Deliver Cyberpunk Thrills on Streamify

    July 22, 2025

    Shadow War Joins Nexus Night to Redefine DeFi

    July 19, 2025

    ONDO price rallies on 21Shares’ ETF filing and major exchange listing

    July 23, 2025

    Bank of England Considers Abandoning Digital Pound CBDC Project Amid Growing Opposition

    July 23, 2025

    Ethereum Price Prediction – $4,096 Breakout or Pullback to $3,525?

    July 23, 2025

    Solana's SOL Could Hit $500 in This Bull Run, Says Analyst, as Upexi Boosts Holdings to 1.8M SOL

    July 23, 2025
  • Legal
    1. Taxes & Regulation
    2. Adoption
    3. View All

    The Mad Journey from Terra to GENIUS

    July 23, 2025

    Citadel urges SEC caution on tokenized securities initiative

    July 23, 2025

    Trump to Sign the Historic GENIUS Act Into Law. What Does It Mean for Crypto?

    July 23, 2025

    FBI drops probe into Kraken founder Jesse Powell, returns seized devices

    July 23, 2025

    Public companies now hold $3.2B worth of Ethereum, swelling past 865,000 ETH

    July 23, 2025

    Stablecoins infiltrate deeper into global finance as Western Union enters crypto

    July 22, 2025

    GENIUS Act makes immediate impact as JP Morgan looks to allow crypto as collateral for lending

    July 22, 2025

    Ethena launches StablecoinX as ENA climbs 8% and USDe supply crosses $6B

    July 22, 2025

    ONDO price rallies on 21Shares’ ETF filing and major exchange listing

    July 23, 2025

    Bank of England Considers Abandoning Digital Pound CBDC Project Amid Growing Opposition

    July 23, 2025

    Ethereum Price Prediction – $4,096 Breakout or Pullback to $3,525?

    July 23, 2025

    Solana's SOL Could Hit $500 in This Bull Run, Says Analyst, as Upexi Boosts Holdings to 1.8M SOL

    July 23, 2025
  • Analysis

    Trader Says One Dogecoin Competitor Primed for New Leg Up, Predicts New All-Time Highs for Bitcoin

    July 23, 2025

    Solana staking ETF hits $100 million mark at record pace

    July 22, 2025

    Ali Martinez Predicts $15 Target Ahead

    July 22, 2025

    Ark Invest pivots to BitMine amid rising Ethereum treasury

    July 22, 2025

    XRP Price Breakout: Analyst Targets $6 Next

    July 22, 2025
  • Learn
    1. Education
    2. Wallets and Exchanges
    3. View All

    What Is Tokenization?

    July 11, 2025

    What Are Internet Capital Markets? Why Companies Are Launching Meme Coins

    June 16, 2025

    What is a Corporate Bitcoin Treasury? The Strategy Behind Companies Holding Crypto

    May 27, 2025

    What Are Tokenized Real-World Assets? Putting Physical Value On-Chain With RWAs

    May 19, 2025

    Coinbase starts CFTC-regulated perpetuals for US traders, offering 10x leverage and 0.02% fees

    July 23, 2025

    Telegram’s TON Wallet goes live in US with eye on 87m users

    July 23, 2025

    BitGo joins flurry of crypto firms eyeing IPOs

    July 22, 2025

    Coinbase stock hits all-time high amid legislative triumphs

    July 19, 2025

    ONDO price rallies on 21Shares’ ETF filing and major exchange listing

    July 23, 2025

    Bank of England Considers Abandoning Digital Pound CBDC Project Amid Growing Opposition

    July 23, 2025

    Ethereum Price Prediction – $4,096 Breakout or Pullback to $3,525?

    July 23, 2025

    Solana's SOL Could Hit $500 in This Bull Run, Says Analyst, as Upexi Boosts Holdings to 1.8M SOL

    July 23, 2025
  • Tools
    • Market Overview
    • Converter
Buy Crypto NewsBuy Crypto News
Home»Security and Privacy»Compromised AI Library Delivers Cryptocurrency Miner via PyPI
Compromised AI Library Delivers Cryptocurrency Miner via PyPI
Security and Privacy

Compromised AI Library Delivers Cryptocurrency Miner via PyPI

December 10, 2024No Comments2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

A Compromised Version of Ultralytics AI Library Found to Deliver Cryptocurrency Mining Payload

A recent discovery by ReversingLabs researchers has revealed that a compromised version of the popular ultralytics AI library was used to deliver a cryptocurrency mining payload. This security breach was traced back to a vulnerability in the library’s build environment, which was exploited through a known GitHub Actions script injection flaw.

Details of the Incident

On December 4, version 8.3.41 of ultralytics was released on the Python Package Index (PyPI) with malicious code that downloaded the XMRig coin miner. The attackers behind this incident employed a sophisticated technique to inject the malicious payloads into the repository, bypassing code reviews and potentially putting a large user base at risk.

Unlike the recent compromise of the npm package @solana/web3.js, which was caused by a compromise of a maintainer account, this breach was the result of intrusion into the build environment through a known GitHub Actions Script Injection vulnerability reported by security researcher Adnan Khan. By crafting pull requests with code embedded in branch titles, the attackers were able to execute arbitrary code.

Potential Impact and Response

Ultralytics, with over 30,000 stars on GitHub and nearly 60 million downloads on PyPI, had the potential to impact a significant number of users. The situation was further exacerbated when version 8.3.42, released to address the issue, also contained the same malicious code. A clean version, 8.3.43, was eventually made available to resolve the issue.

While the compromised code primarily deployed a cryptocurrency miner, researchers warned that the same vector could have been used to distribute more harmful malware, such as backdoors or remote access Trojans. The malicious code specifically targeted downloads.py and model.py, with functionality designed to assess system configurations and deliver platform-specific payloads.

See also  Police Celebrate $130m Cyber Busts

Identification of Attackers

The attack was linked to a GitHub account named openimbot, which exhibited suspicious activity patterns indicating a possible account takeover. The attackers leveraged branch names to embed payload code, enabling them to gain backdoor access to the environment through crafted pull requests.

Conclusion

This incident highlights the critical importance of software supply chain security and the need for constant vigilance to protect against such vulnerabilities. By staying informed about potential threats and maintaining robust security measures, developers and users can help prevent similar compromises in the future.

Compromised Cryptocurrency Delivers Library miner PyPI
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Accounting Firm Targeted by Malware Campaign Using New Crypter

July 22, 2025

Grok refuses to pick winner for Crypto Rover competition citing ZachXBT pump and dump evidence

July 21, 2025

Nasdaq-listed miner BTC Digital to swap Bitcoin for Ethereum in treasury overhaul

July 20, 2025

AIXA Miner Launches AI-Powered Cloud Mining Ecosystem Amid Surge in Blockchain Adoption

July 20, 2025
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Data sovereignty can redefine the global economic markets

June 15, 2025

Crypto Perpetuals Trading Doubles to $58.5T in 2024 While Binance’s Market Share Declines 20%

March 17, 2025

Galaxy Digital Unloads Ethereum and Accumulates Solana As $105,480,000 in ETH Deposited to Binance: Lookonchain

April 24, 2025
Price Chart


Explore insights on crypto, blockchain, taxes, and security. Stay informed with expert guides, tips, and the latest trends to navigate the digital asset world confidently


We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

ONDO price rallies on 21Shares’ ETF filing and major exchange listing

July 23, 2025

Bank of England Considers Abandoning Digital Pound CBDC Project Amid Growing Opposition

July 23, 2025

Ethereum Price Prediction – $4,096 Breakout or Pullback to $3,525?

July 23, 2025
Get Informed

Subscribe to Updates

Get the latest creative news From BuyCryptoNews directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
© 2025 BuyCryptoNews - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.