CI/CD Compromise 2024 Incident #49

Ultralytics YOLO

Estimated Financial Impact
$5-10M
Blast Radius
60M total downloads; ~10% of cloud environments

What Happened

Attackers exploited a GitHub Actions script injection vulnerability to poison the build cache of Ultralytics YOLO and inject an XMRig cryptominer into published PyPI packages. YOLO had ~60M total downloads. Wiz found the malicious versions in ~10% of scanned cloud environments.

✓

Risk Guard: Caught

PACKAGE_ACTIVE_MALWARE + PACKAGE_INSTALL_SCRIPTS; ARTIFACT_HASH_MISMATCH detects build cache poisoning

Risk Guard Check Codes That Flag This Incident

PACKAGE_ACTIVE_MALWAREARTIFACT_HASH_MISMATCH

How Every Tool Performed

2 Caught 1 Partial 3 Missed
Tool Verdict Details
OSS Risk Guard Caught PACKAGE_ACTIVE_MALWARE + PACKAGE_INSTALL_SCRIPTS; ARTIFACT_HASH_MISMATCH detects build cache poisoning
Sonatype (Nexus) Partial Limited ecosystem coverage for this attack
Socket Caught Behavioral analysis detects malicious payload.
Snyk Missed No malware detection capability
Black Duck Missed No malware detection capability
Endor Labs Missed No malware detection capability
← SolarWinds / Sunburst GhostAction campaign →