United States
USA
In December 2024, the Ultralytics project suffered a software supply-chain compromise through its GitHub Actions workflows and PyPI publishing process. Multiple legitimate ultralytics releases were modified to contain unauthorized code that downloaded and executed XMRig cryptocurrency-mining software when users instantiated YOLO models, compromising the integrity of the software distribution channel.
Estimated severity
72 / 100
Source reliability
93 / 100
Approximate Date
04/12/2024
Targeted Company
ULTRALYTICS
Distribution & Fulfillment
Procurement & Sourcing
Production & Manufacturing
Sales (Retail & Ecommerce)
Warehousing
Service Delivery
Unrecognized Impact
Supply Chain Relations
No information
United States
USA
No other affected countries reported
Target country
United States
Affected countries
Impacted regions
No information
Duration
No information
Financial impact (USD M)
No information
Impact types
Affected sectors
Affected departments
Attack types
Attributed threat actors
No information
Please rotate your phone