Navigate Select ESC Close

Popular Python Package Becomes Crypto Miner

2024-12-12 Science & Technology
201.4k
4.0k
286
ThePrimeTime
ThePrimeTime
1.1m subscribers

Unlock all features

FREE: Get instant access to 10 AI summaries, chats, or transcripts per day.

Description

Twitch https://twitch.tv/ThePrimeagen Discord https://discord.gg/ThePrimeagen Become Backend Dev: https://boot.dev/prime (plus i make courses for them) This is also the best way to support me is to support yourself becoming a better backend engineer. ### LINKS https://blog.yossarian.net/2024/12/06/zizmor-ultralytics-injection By: William Woodruff | https://x.com/8x5clPW2 Great News? Want me to research and create video????: https://www.reddit.com/r/ThePrimeagen Kinesis Advantage 360: https://bit.ly/Prime-Kinesis Get production ready SQLite with Turso: https://turso.tech/deeznuts

Top Comments (10)

@xl0xl0xl0 2024-12-12

Ultralytics does vision-related AI stuff, so it's likely the computers infected has GPUs, possibly very powerful ones.

897 8 replies
@WhalesLoveSmash 2024-12-12

Suorised this sort of thing doesn't happen more often.

439 13 replies
@lex_darlog_fun 2024-12-12

15:15 Everything told about CPUs is irrelevant. Ultralytics is a module specifically designed for ML/NN stuff, like LLMs or image generation. So, with a probability of 90%+, the final user has a GPU *and* it's probably a beefy one (maybe even a small GPU cluster) *and* the app this package is used in is intended to utilize this GPU heavily. For example, ComfyUI (one of two most popular web-UIs for StableDiffusion) had to specifically warn their users of this module being compromised.

399 9 replies
@TomNook. 2024-12-12

This is why I never allow Dependabot to auto commit

164 9 replies
@TomNook. 2024-12-12

I feel sorry for all the people who have similar names to Jia Tan. Similar to all the women called Karen who are nice

146 1 replies
@set-your-handle-c3w 2024-12-12

Since this is targeting ML, a lot of the machines that are going to be using this package will have GPUs, which mine at a much better rate. Additionally if the threat actor has some sort of persistence, there may be a number of machines mining for an extended period of time.

131 3 replies
@Benjam1981 2024-12-12

The second hack was their fault. If you have a supply chain attack, you should immediately rotate your keys. That's common knowledge

120 2 replies
@daliborilic5358 2024-12-12

The whole of internet is held up by toothpicks and tape...

64 7 replies
@scorsoneenterprises 2024-12-12

I’ll never feel like I’m wasting time when I do machine learning from scratch again

52 4 replies
@markcoren2842 2024-12-12

This feels a lot like boundary sensing, where they worked out an effective proof of concept and then did a dry run with a trivial payload. This gives real world metrics for penetration, adoption, durability and detection. There's also a great response profile now. Theoretical attach vectors are all good and well but nothing compares to real world live fire for knowing where to tighten up or tweak.

14

Unlock the Data Inside
Turn Videos into Knowledge

  • Get FREE 10/day: transcripts, summaries, chats
  • Chat with videos, export text & PDF
  • $1 free API credit for RAG, chatbots & research

Free forever plan • All features unlocked

App screenshot