MIT TRACE

MIT CTL Logo
Back to Main Dashboard

Ultralytics build compromise distributes malicious PyPI releases

In December 2024, the Ultralytics project suffered a software supply-chain compromise through its GitHub Actions workflows and PyPI publishing process. Multiple legitimate ultralytics releases were modified to contain unauthorized code that downloaded and executed XMRig cryptocurrency-mining software when users instantiated YOLO models, compromising the integrity of the software distribution channel.

72

Estimated severity

72 / 100

93

Source reliability

93 / 100

Approximate Date

04/12/2024

Targeted Company

ULTRALYTICS

Targeted Company Supply Chain Impact

  1. Distribution & Fulfillment

  2. Procurement & Sourcing

  3. Production & Manufacturing

  4. Sales (Retail & Ecommerce)

  5. Warehousing

  6. Service Delivery

  7. Unrecognized Impact

Supply Chain Relations

No information

Geographic Impact

Country Targeted Company

United States

USA

Other Affected Countries

No other affected countries reported

Target country

United States

Affected countries

United States

Impacted regions

No information

Operational Impact

Duration

No information

Financial impact (USD M)

No information

Impact types

Supply chain data integrity impact

Affected sectors

Technology & IT Services

Affected departments

Information Technology

Attack Profile

Attack types

Software supply chain compromiseData modification

Attributed threat actors

No information

Sources

Please rotate your phone

MIT TRACE is optimized for landscape orientation on mobile.