{"id":1572,"date":"2025-05-27T16:00:00","date_gmt":"2025-05-27T13:00:00","guid":{"rendered":"https:\/\/trustcrypt.com\/discovery-of-malicious-machine-learning-model-attacks-on-pypi\/"},"modified":"2025-05-27T16:00:00","modified_gmt":"2025-05-27T13:00:00","slug":"discovery-of-malicious-machine-learning-model-attacks-on-pypi","status":"publish","type":"post","link":"https:\/\/trustcrypt.com\/ar\/discovery-of-malicious-machine-learning-model-attacks-on-pypi\/","title":{"rendered":"Discovery of Malicious Machine Learning Model Attacks on PyPI"},"content":{"rendered":"<p>A recent campaign targeting machine learning models has been uncovered within the Python Package Index (PyPI) by cybersecurity experts. Researchers from ReversingLabs reported that malicious actors are utilizing the Pickle file format to disguise malware within seemingly legitimate AI-related software packages.<\/p>\n<p>In this instance, three deceptive packages were identified: PLACEHOLDER<em>3dfdf306ebdb86d4, PLACEHOLDER<\/em>daeee21df8fa64a4, and <code>aliyun-ai-labs-sdk<\/code>. These were falsely promoted as a Python SDK for Alibaba\u2019s AI services. Contrary to their claims, these packages bore no authentic AI code. Instead, they incorporated an infostealer payload hidden within PyTorch models, which are essentially archived Pickle files.<\/p>\n<p>Once installed, the payload was triggered from the initialization script, designed to extract critical data, including:<\/p>\n<p>&#8211; User and network information<br \/>\n&#8211; Organizational affiliation of the target machine<br \/>\n&#8211; Contents of the <code>.gitconfig<\/code> file<\/p>\n<p>Alarmingly, the malicious models made efforts to detect developers linked to the Chinese video conferencing platform AliMeeting, indicating a specific regional targeting strategy.<\/p>\n<h3>The Perils of PyTorch and Pickle<\/h3>\n<p>This incident underscores a rising trend in the exploitation of machine learning model formats. According to ReversingLabs, the use of Pickle allows serialized Python objects to run arbitrary code, making it an attractive vector for cybercriminals looking to bypass standard security measures. Of the malicious packages identified, two successfully utilized this method to distribute functional malware.<\/p>\n<p>The researchers highlighted a significant gap in existing security tools&#8217; capabilities to detect embedded malicious actions within machine learning files. \u201cSecurity tools are at a primitive level concerning malicious ML model detection,\u201d stated Karlo Zanki, a reverse engineer at ReversingLabs. \u201cLegacy security tooling currently lacks the necessary functionality.\u201d<\/p>\n<p>The infected packages were available on PyPI for a brief period, accumulating approximately 1,600 downloads before their prompt removal. While the specific tactics employed to entice users remain uncertain, the potential for social engineering or phishing tactics is highly suspected.<\/p>\n<p>As AI and machine learning become integral to software development processes, this attack emphasizes the pressing need for enhanced validation practices and the implementation of zero-trust principles in the management of machine learning artifacts.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A recent campaign targeting machine learning models has been uncovered within the Python Package Index (PyPI) by cybersecurity experts. Researchers&#8230;<\/p>\n","protected":false},"author":1,"featured_media":1573,"comment_status":"open","ping_status":"closed","sticky":false,"template":"Default","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[28],"tags":[73,655,54],"class_list":["post-1572","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog","tag-cybersecurity","tag-machine-learning","tag-malware"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v25.0 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Discovery of Malicious Machine Learning Model Attacks on PyPI - Trustcrypt<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/trustcrypt.com\/ar\/discovery-of-malicious-machine-learning-model-attacks-on-pypi\/\" \/>\n<meta property=\"og:locale\" content=\"ar_AR\" \/>\n<meta property=\"og:locale:alternate\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Discovery of Malicious Machine Learning Model Attacks on PyPI\" \/>\n<meta property=\"og:description\" content=\"A recent campaign targeting machine learning models has been uncovered within the Python Package Index (PyPI) by cybersecurity experts. Researchers...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/trustcrypt.com\/ar\/discovery-of-malicious-machine-learning-model-attacks-on-pypi\/\" \/>\n<meta property=\"og:site_name\" content=\"Trustcrypt\" \/>\n<meta property=\"article:published_time\" content=\"2025-05-27T13:00:00+00:00\" \/>\n<meta name=\"author\" content=\"Trustscrypt\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u0643\u064f\u062a\u0628 \u0628\u0648\u0627\u0633\u0637\u0629\" \/>\n\t<meta name=\"twitter:data1\" content=\"Trustscrypt\" \/>\n\t<meta name=\"twitter:label2\" content=\"\u0648\u0642\u062a \u0627\u0644\u0642\u0631\u0627\u0621\u0629 \u0627\u0644\u0645\u064f\u0642\u062f\u0651\u0631\" \/>\n\t<meta name=\"twitter:data2\" content=\"\u062f\u0642\u064a\u0642\u062a\u0627\u0646\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/trustcrypt.com\/discovery-of-malicious-machine-learning-model-attacks-on-pypi\/\",\"url\":\"https:\/\/trustcrypt.com\/discovery-of-malicious-machine-learning-model-attacks-on-pypi\/\",\"name\":\"Discovery of Malicious Machine Learning Model Attacks on PyPI\",\"isPartOf\":{\"@id\":\"https:\/\/trustcrypt.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/trustcrypt.com\/discovery-of-malicious-machine-learning-model-attacks-on-pypi\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/trustcrypt.com\/discovery-of-malicious-machine-learning-model-attacks-on-pypi\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/trustcrypt.com\/wp-content\/uploads\/2025\/05\/discovery-of-malicious-machine-learning-model-attacks-on-pypi.webp\",\"datePublished\":\"2025-05-27T13:00:00+00:00\",\"author\":{\"@id\":\"https:\/\/trustcrypt.com\/#\/schema\/person\/469b1cf97b9f7ea4e4d7fa31689dfa9f\"},\"inLanguage\":\"ar\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/trustcrypt.com\/discovery-of-malicious-machine-learning-model-attacks-on-pypi\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"ar\",\"@id\":\"https:\/\/trustcrypt.com\/discovery-of-malicious-machine-learning-model-attacks-on-pypi\/#primaryimage\",\"url\":\"https:\/\/trustcrypt.com\/wp-content\/uploads\/2025\/05\/discovery-of-malicious-machine-learning-model-attacks-on-pypi.webp\",\"contentUrl\":\"https:\/\/trustcrypt.com\/wp-content\/uploads\/2025\/05\/discovery-of-malicious-machine-learning-model-attacks-on-pypi.webp\",\"width\":1792,\"height\":1024,\"caption\":\"Discovery of Malicious Machine Learning Model Attacks on PyPI\"},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/trustcrypt.com\/#website\",\"url\":\"https:\/\/trustcrypt.com\/\",\"name\":\"Trustcrypt\",\"description\":\"\u0627\u0644\u0623\u0645\u0646 \u0647\u0648 \u0627\u0633\u0645\u0646\u0627 \u0627\u0644\u062b\u0627\u0646\u064a\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/trustcrypt.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"ar\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/trustcrypt.com\/#\/schema\/person\/469b1cf97b9f7ea4e4d7fa31689dfa9f\",\"name\":\"Trustscrypt\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"ar\",\"@id\":\"https:\/\/trustcrypt.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/4c36ff3376565a0f4981e9397667feb08d5e09acacce32a52ea4a3f628e03692?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/4c36ff3376565a0f4981e9397667feb08d5e09acacce32a52ea4a3f628e03692?s=96&d=mm&r=g\",\"caption\":\"Trustscrypt\"},\"sameAs\":[\"http:\/\/trustcrypt.com\"],\"url\":\"https:\/\/trustcrypt.com\/ar\/author\/trustscrypt\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Discovery of Malicious Machine Learning Model Attacks on PyPI - Trustcrypt","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/trustcrypt.com\/ar\/discovery-of-malicious-machine-learning-model-attacks-on-pypi\/","og_locale":"ar_AR","og_type":"article","og_title":"[:en]Discovery of Malicious Machine Learning Model Attacks on PyPI[:] - Trustcrypt","og_description":"A recent campaign targeting machine learning models has been uncovered within the Python Package Index (PyPI) by cybersecurity experts. Researchers...","og_url":"https:\/\/trustcrypt.com\/ar\/discovery-of-malicious-machine-learning-model-attacks-on-pypi\/","og_site_name":"Trustcrypt","article_published_time":"2025-05-27T13:00:00+00:00","author":"Trustscrypt","twitter_card":"summary_large_image","twitter_misc":{"\u0643\u064f\u062a\u0628 \u0628\u0648\u0627\u0633\u0637\u0629":"Trustscrypt","\u0648\u0642\u062a \u0627\u0644\u0642\u0631\u0627\u0621\u0629 \u0627\u0644\u0645\u064f\u0642\u062f\u0651\u0631":"\u062f\u0642\u064a\u0642\u062a\u0627\u0646"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/trustcrypt.com\/discovery-of-malicious-machine-learning-model-attacks-on-pypi\/","url":"https:\/\/trustcrypt.com\/discovery-of-malicious-machine-learning-model-attacks-on-pypi\/","name":"Discovery of Malicious Machine Learning Model Attacks on PyPI","isPartOf":{"@id":"https:\/\/trustcrypt.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/trustcrypt.com\/discovery-of-malicious-machine-learning-model-attacks-on-pypi\/#primaryimage"},"image":{"@id":"https:\/\/trustcrypt.com\/discovery-of-malicious-machine-learning-model-attacks-on-pypi\/#primaryimage"},"thumbnailUrl":"https:\/\/trustcrypt.com\/wp-content\/uploads\/2025\/05\/discovery-of-malicious-machine-learning-model-attacks-on-pypi.webp","datePublished":"2025-05-27T13:00:00+00:00","author":{"@id":"https:\/\/trustcrypt.com\/#\/schema\/person\/469b1cf97b9f7ea4e4d7fa31689dfa9f"},"inLanguage":"ar","potentialAction":[{"@type":"ReadAction","target":["https:\/\/trustcrypt.com\/discovery-of-malicious-machine-learning-model-attacks-on-pypi\/"]}]},{"@type":"ImageObject","inLanguage":"ar","@id":"https:\/\/trustcrypt.com\/discovery-of-malicious-machine-learning-model-attacks-on-pypi\/#primaryimage","url":"https:\/\/trustcrypt.com\/wp-content\/uploads\/2025\/05\/discovery-of-malicious-machine-learning-model-attacks-on-pypi.webp","contentUrl":"https:\/\/trustcrypt.com\/wp-content\/uploads\/2025\/05\/discovery-of-malicious-machine-learning-model-attacks-on-pypi.webp","width":1792,"height":1024,"caption":"Discovery of Malicious Machine Learning Model Attacks on PyPI"},{"@type":"WebSite","@id":"https:\/\/trustcrypt.com\/#website","url":"https:\/\/trustcrypt.com\/","name":"Trustcrypt","description":"\u0627\u0644\u0623\u0645\u0646 \u0647\u0648 \u0627\u0633\u0645\u0646\u0627 \u0627\u0644\u062b\u0627\u0646\u064a","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/trustcrypt.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"ar"},{"@type":"Person","@id":"https:\/\/trustcrypt.com\/#\/schema\/person\/469b1cf97b9f7ea4e4d7fa31689dfa9f","name":"Trustscrypt","image":{"@type":"ImageObject","inLanguage":"ar","@id":"https:\/\/trustcrypt.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/4c36ff3376565a0f4981e9397667feb08d5e09acacce32a52ea4a3f628e03692?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/4c36ff3376565a0f4981e9397667feb08d5e09acacce32a52ea4a3f628e03692?s=96&d=mm&r=g","caption":"Trustscrypt"},"sameAs":["http:\/\/trustcrypt.com"],"url":"https:\/\/trustcrypt.com\/ar\/author\/trustscrypt\/"}]}},"_links":{"self":[{"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/posts\/1572","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/comments?post=1572"}],"version-history":[{"count":0,"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/posts\/1572\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/media\/1573"}],"wp:attachment":[{"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/media?parent=1572"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/categories?post=1572"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/tags?post=1572"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}