Close Menu
  • Latest News
    • Bitcoin
    • Ethereum
    • Altcoins
    • Meme Coins
  • DeFi
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • Gaming
  • Legal
    • Taxes & Regulation
    • Adoption
  • Analysis
  • Learn
    • Education
    • Wallets and Exchanges
  • Tools
    • Market Overview
    • Converter
What's Hot

Ripple CEO Brad Garlinghouse sees XRP capturing 14% of SWIFT’s market in five years

June 15, 2025

Here’s why Aerodrome Finance’s AERO token price is soaring

June 15, 2025

Donald Trump Warns Fed: Slash Rates or I’ll “Force Something” – Powell’s Job Still Safe

June 15, 2025
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
Facebook X (Twitter) Instagram
Buy Crypto NewsBuy Crypto News
  • Latest News
    1. Bitcoin
    2. Ethereum
    3. Altcoins
    4. Meme Coins
    5. View All

    $1.14 Billion Wiped Out as Market Faces Double Attack? 

    June 15, 2025

    Here Are the Possible Bearish Targets for Bitcoin After BTC Fails To Break Out Above Major Level, According to Crypto Analyst

    June 14, 2025

    Bitcoin Bounces to $106K After Iran-Israel Jitters, but Analysts Warn of Deeper Pullback

    June 14, 2025

    The 30,000-Foot View Of The Oslo Freedom Forum

    June 14, 2025

    Lido’s Ethereum staking share drops 9% in 2025 – Can LDO flip 75% losses? 

    June 15, 2025

    What’s making Ethereum more attractive than Bitcoin right now

    June 14, 2025

    Mapping Bitcoin, Ethereum’s moves amid Middle Eastern tensions, tariff wars

    June 14, 2025

    Ethereum: Smart money buys the dip as ETH dives 9% – What’s next?

    June 14, 2025

    Mapping Optimism’s future: Major breakout or a pullback?

    June 14, 2025

    Billionaire Snaps Up $100M Of Trump Coin After Investigation Ends

    June 14, 2025

    Bitcoin ETF inflows explode $970 mln: Will BTC ride this wave to more gains?

    June 14, 2025

    Several Fund Managers Files Updated Form S-1 With U.S. SEC

    June 14, 2025

    Pepe, BMT, CAKE: Crypto Activity Heats Up

    March 18, 2025

    SHIB Burns Over Half a Billion Tokens, Price Surges Over 7%

    March 17, 2025

    DOGE Sees Massive User Growth: Active Addresses Up 400%

    March 15, 2025

    Shiba Inu (SHIB) Price Analysis: Bullish Hints, Bearish Trend

    March 15, 2025

    Ripple CEO Brad Garlinghouse sees XRP capturing 14% of SWIFT’s market in five years

    June 15, 2025

    Here’s why Aerodrome Finance’s AERO token price is soaring

    June 15, 2025

    Donald Trump Warns Fed: Slash Rates or I’ll “Force Something” – Powell’s Job Still Safe

    June 15, 2025

    Lido’s Ethereum staking share drops 9% in 2025 – Can LDO flip 75% losses? 

    June 15, 2025
  • DeFi

    Here’s why Aerodrome Finance’s AERO token price is soaring

    June 15, 2025

    Sonic poised for deeper correction ahead despite a potential Coinbase listing

    June 14, 2025

    HYPE steadies after sharp pullback from ATH amid market tumble

    June 14, 2025

    Ethereum Foundation Stakes $1.25M War Chest to Shield Tornado Cash’s Roman Storm

    June 14, 2025

    Cardano’s $100M plan to tackle DeFi and stablecoin challenges

    June 14, 2025
  • Tech
    1. Blockchain
    2. Security and Privacy
    3. View All

    Donald Trump Warns Fed: Slash Rates or I’ll “Force Something” – Powell’s Job Still Safe

    June 15, 2025

    The Real Lifestyle Teams Up with Bitsolara for Gamified Web3 Transport Innovation

    June 14, 2025

    Stablecoin Surge: Market Cap Hits Record $228B in 2025 Amid Trading Boom and Trump-Era Clarity

    June 14, 2025

    Startup DIMO Launches DePIN Venture in Japan to Help Automakers Monetize Vehicle Data

    June 14, 2025

    Coinbase data breach spills offline as victims get scam mail

    June 6, 2025

    Cryptojacking Campaign Targets DevOps Servers Including Nomad

    June 3, 2025

    Sophisticated Malware Campaign Targets Windows and Linux Systems

    June 2, 2025

    US Treasury sanctions Philippines tech firm over aiding $200 million pig butchering spree

    May 31, 2025

    Ripple CEO Brad Garlinghouse sees XRP capturing 14% of SWIFT’s market in five years

    June 15, 2025

    Here’s why Aerodrome Finance’s AERO token price is soaring

    June 15, 2025

    Donald Trump Warns Fed: Slash Rates or I’ll “Force Something” – Powell’s Job Still Safe

    June 15, 2025

    Lido’s Ethereum staking share drops 9% in 2025 – Can LDO flip 75% losses? 

    June 15, 2025
  • Web 3
    1. Web3 News
    2. Gaming
    3. View All

    Ripplecoin Mining Free Cloud Mining App, High-yield Cloud Mining Investment Guide for BTC and XRP Holders

    June 14, 2025

    Digital Forensics Market 2025-2033: Key Players Include Cellebrite, Magnet Forensics, and AccessData

    June 14, 2025

    Sunny Mining achieves breakthrough AI-driven technology,Becoming a profitable milestone in the cloud mining industry

    June 14, 2025

    Wondershare Announces Breakthrough Solution for Recovering Data from Android Devices with Broken Screens

    June 14, 2025

    Why are big games building on Avalanche instead of Ethereum?

    June 14, 2025

    NFT – what is it and why is it needed?

    June 13, 2025

    ‘FIFA Rivals’ Launches—Why Mythical Games Thinks It’ll Hit Bigger Than ‘NFL Rivals’

    June 13, 2025

    Off The Grid active wallets hold steady ahead of Steam launch

    June 13, 2025

    Ripple CEO Brad Garlinghouse sees XRP capturing 14% of SWIFT’s market in five years

    June 15, 2025

    Here’s why Aerodrome Finance’s AERO token price is soaring

    June 15, 2025

    Donald Trump Warns Fed: Slash Rates or I’ll “Force Something” – Powell’s Job Still Safe

    June 15, 2025

    Lido’s Ethereum staking share drops 9% in 2025 – Can LDO flip 75% losses? 

    June 15, 2025
  • Legal
    1. Taxes & Regulation
    2. Adoption
    3. View All

    Cynthia Lummis Proposes Artificial Intelligence Bill, Requiring AI Firms to Disclose Technicals

    June 14, 2025

    Ethereum Foundation pledges $1M to Storm’s defense, entities boost Pertsev appeal

    June 14, 2025

    Latest Motion Could Make or Break It

    June 14, 2025

    Liquid Staking: The Most Complete Guide on the Internet

    June 14, 2025

    Ripple CEO Brad Garlinghouse sees XRP capturing 14% of SWIFT’s market in five years

    June 15, 2025

    XRP’s corporate treasury investments near $1 billion

    June 14, 2025

    SharpLink leads with $463M Ethereum treasury move

    June 14, 2025

    Anthony Pompliano planning $750 million Bitcoin-focused investment firm via SPAC

    June 14, 2025

    Ripple CEO Brad Garlinghouse sees XRP capturing 14% of SWIFT’s market in five years

    June 15, 2025

    Here’s why Aerodrome Finance’s AERO token price is soaring

    June 15, 2025

    Donald Trump Warns Fed: Slash Rates or I’ll “Force Something” – Powell’s Job Still Safe

    June 15, 2025

    Lido’s Ethereum staking share drops 9% in 2025 – Can LDO flip 75% losses? 

    June 15, 2025
  • Analysis

    This Dogecoin Rival Could Go Higher Amid Increased Whale Activity, Says Analytics Platform Santiment

    June 14, 2025

    Bitcoin (BTC) Price Drop To $105k Divides Crypto Traders: What Next?

    June 14, 2025

    Polkadot seeks stability with $2M Bitcoin reserve strategy amid DOT downturn

    June 13, 2025

    Is the Capital Rotation Already Underway?

    June 13, 2025

    Leading Stablecoin Issuer Tether Invests $89,000,000 Into Precious Metals Royalty Company To Deepen Exposure to Gold

    June 13, 2025
  • Learn
    1. Education
    2. Wallets and Exchanges
    3. View All

    What is a Corporate Bitcoin Treasury? The Strategy Behind Companies Holding Crypto

    May 27, 2025

    What Are Tokenized Real-World Assets? Putting Physical Value On-Chain With RWAs

    May 19, 2025

    Users Taunt Grok After xAI Says Modifications Were Made to Spit out ‘White Genocide’ Claim

    May 16, 2025

    What Is Base? The Ethereum Layer-2 Network Launched by Coinbase

    April 29, 2025

    Every crypto trade will soon happen inside your wallet

    June 14, 2025

    Coinbase to launch CFTC-cleared perpetual futures trading, Bitcoin-backed credit card for US customers

    June 13, 2025

    FTX continues to exclude Nigeria and China in remaining creditor repayments but includes Payoneer

    June 12, 2025

    BiT Global drops Coinbase lawsuit over wrapped Bitcoin delisting

    June 10, 2025

    Ripple CEO Brad Garlinghouse sees XRP capturing 14% of SWIFT’s market in five years

    June 15, 2025

    Here’s why Aerodrome Finance’s AERO token price is soaring

    June 15, 2025

    Donald Trump Warns Fed: Slash Rates or I’ll “Force Something” – Powell’s Job Still Safe

    June 15, 2025

    Lido’s Ethereum staking share drops 9% in 2025 – Can LDO flip 75% losses? 

    June 15, 2025
  • Tools
    • Market Overview
    • Converter
Buy Crypto NewsBuy Crypto News
Home»Security and Privacy»Compromised AI Library Delivers Cryptocurrency Miner via PyPI
Compromised AI Library Delivers Cryptocurrency Miner via PyPI
Security and Privacy

Compromised AI Library Delivers Cryptocurrency Miner via PyPI

December 10, 2024No Comments2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

A Compromised Version of Ultralytics AI Library Found to Deliver Cryptocurrency Mining Payload

A recent discovery by ReversingLabs researchers has revealed that a compromised version of the popular ultralytics AI library was used to deliver a cryptocurrency mining payload. This security breach was traced back to a vulnerability in the library’s build environment, which was exploited through a known GitHub Actions script injection flaw.

Details of the Incident

On December 4, version 8.3.41 of ultralytics was released on the Python Package Index (PyPI) with malicious code that downloaded the XMRig coin miner. The attackers behind this incident employed a sophisticated technique to inject the malicious payloads into the repository, bypassing code reviews and potentially putting a large user base at risk.

Unlike the recent compromise of the npm package @solana/web3.js, which was caused by a compromise of a maintainer account, this breach was the result of intrusion into the build environment through a known GitHub Actions Script Injection vulnerability reported by security researcher Adnan Khan. By crafting pull requests with code embedded in branch titles, the attackers were able to execute arbitrary code.

Potential Impact and Response

Ultralytics, with over 30,000 stars on GitHub and nearly 60 million downloads on PyPI, had the potential to impact a significant number of users. The situation was further exacerbated when version 8.3.42, released to address the issue, also contained the same malicious code. A clean version, 8.3.43, was eventually made available to resolve the issue.

While the compromised code primarily deployed a cryptocurrency miner, researchers warned that the same vector could have been used to distribute more harmful malware, such as backdoors or remote access Trojans. The malicious code specifically targeted downloads.py and model.py, with functionality designed to assess system configurations and deliver platform-specific payloads.

See also  Cryptocurrency clicker game Crystal Kami in Telegram from Holiverse by Lado Okhotnikov

Identification of Attackers

The attack was linked to a GitHub account named openimbot, which exhibited suspicious activity patterns indicating a possible account takeover. The attackers leveraged branch names to embed payload code, enabling them to gain backdoor access to the environment through crafted pull requests.

Conclusion

This incident highlights the critical importance of software supply chain security and the need for constant vigilance to protect against such vulnerabilities. By staying informed about potential threats and maintaining robust security measures, developers and users can help prevent similar compromises in the future.

Compromised Cryptocurrency Delivers Library miner PyPI
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

APT Miner uses clean energy cloud mining to earn Bitcoin, XRP and Dogecoin for free

June 7, 2025

Coinbase data breach spills offline as victims get scam mail

June 6, 2025

SEC’s Crypto Task Force Chair Hester Peirce Delivers Definitive Take on TRUMP and All Memecoins

June 4, 2025

Cryptojacking Campaign Targets DevOps Servers Including Nomad

June 3, 2025
Add A Comment
Leave A Reply Cancel Reply

Top Posts

SEC delays decision on Bitwise, 21Shares Solana ETF applications, opens public consultation

May 22, 2025

XRP Targets $19 Or $45 In Possible Blow-Off Top, Analyst Predicts

April 12, 2025

Need for Speed – Only Ultra-Fast Blockchains Will Win the Adoption Race (Opinion)

March 15, 2025
Price Chart


Explore insights on crypto, blockchain, taxes, and security. Stay informed with expert guides, tips, and the latest trends to navigate the digital asset world confidently


We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Ripple CEO Brad Garlinghouse sees XRP capturing 14% of SWIFT’s market in five years

June 15, 2025

Here’s why Aerodrome Finance’s AERO token price is soaring

June 15, 2025

Donald Trump Warns Fed: Slash Rates or I’ll “Force Something” – Powell’s Job Still Safe

June 15, 2025
Get Informed

Subscribe to Updates

Get the latest creative news From BuyCryptoNews directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
© 2025 BuyCryptoNews - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.