Attackers exploited a GitHub Actions script injection vulnerability to poison the build cache of Ultralytics YOLO and inject an XMRig cryptominer into published PyPI packages. YOLO had ~60M total downloads. Wiz found the malicious versions in ~10% of scanned cloud environments.
PACKAGE_ACTIVE_MALWARE + PACKAGE_INSTALL_SCRIPTS; ARTIFACT_HASH_MISMATCH detects build cache poisoning
| Tool | Verdict | Details |
|---|---|---|
| OSS Risk Guard | Caught | PACKAGE_ACTIVE_MALWARE + PACKAGE_INSTALL_SCRIPTS; ARTIFACT_HASH_MISMATCH detects build cache poisoning |
| Sonatype (Nexus) | Partial | Limited ecosystem coverage for this attack |
| Socket | Caught | Behavioral analysis detects malicious payload. |
| Snyk | Missed | No malware detection capability |
| Black Duck | Missed | No malware detection capability |
| Endor Labs | Missed | No malware detection capability |