Ultralytics Hit by Supply Chain Attack Through GitHub Branch Name Injection
by d3lirium - Saturday December 7, 2024 at 12:46 AM
#1
Very interesting attack vector here. Someone used PRs to leak secrets from build pipelines.

Then they used it to poison the release to drop a Monero miner. For the attacker the attack generally yielded very little, but it caused chaos around the world, including downstream applications that used it.

https://www.bleepingcomputer.com/news/se...yptominer/

The blog below has exceptional detail:

https://blog.yossarian.net/2024/12/06/zi...he-payload

There are so many other major open-source projects vulnerable to the same kind of vulnerability.
Reply
#2
where can we download the data?
Reply
#3
payload details were awesome, nice work from them
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  NO LOGS VPN: Best VPN for clear and dark web Crockett 361 66,494 1 hour ago
Last Post: btl3r
  ? Bill Gates Shares Microsoft’s Original Source Code Teko 9 732 Feb 05, 2026, 11:11 AM
Last Post: xeyro
  [LLM] Malware dev and Hacking is getting easier brianoconnor 5 308 Feb 02, 2026, 01:09 PM
Last Post: pam2s
  ShinyHunters claim hacks of Okta, Microsoft SSO accounts for data theft joepa 0 240 Jan 25, 2026, 11:48 AM
Last Post: joepa
  Microsoft Gave FBI Keys To Unlock Encrypted Data, Exposing Major Privacy Flaw joepa 0 208 Jan 24, 2026, 11:31 AM
Last Post: joepa

Forum Jump:


 Users browsing this forum: 1 Guest(s)