Supply chain, Malware, Threat Intelligence

Malicious PyPI packages exploit ML models to deploy infostealer

System hacked warning alert on laptop computer. Cyber attack on computer network, virus, spyware, malware or malicious software. Cyber security and cybercrime concept. System security technology (3)

Information-stealing malware has been spread through a trio of malicious Python Package Index packages purporting to provide a Python SDK for Alibaba's artificial intelligence services, which have accumulated almost 1,600 downloads prior to their removal from the PyPI repository, reports Infosecurity Magazine.

All of the packages, namely aliyun-ai-labs-snippets-sdk, ai-labs-snippets-sdk, and aliyun-ai-labs-sdk, contained only zipped Pickle files to conceal the infostealing payload, which facilitates the theft of user and network data, targeted machines' organizational affiliations, and .gitconfig file contents, as well as the identification of developers linked to the AliMeeting video conferencing software, according to an analysis from ReversingLabs. Such findings signify escalating risks associated with machine learning model format misuse, with ReversingLabs researchers urging more robust validation and zero-trust practices in ML artifact management. "Security tools are at a primitive level when it comes to malicious ML model detection. Legacy security tooling is currently lacking this required functionality," said ReversingLabs reverse engineer Karlo Zanki.

Related Events

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds