Tag: Broken Pickle Format

Malicious ML Models on Hugging Face Leverage Broken Pickle Format to Evade Detection
News

Malicious ML Models on Hugging Face Leverage Broken Pickle Format to Evade Detection

On Hugging Face, cybersecurity experts discovered two malicious machine learning (ML) models that used an odd method of "broken" pickle files to avoid detection. Karlo Zanki, a researcher at ReversingLabs, told The Hacker News that the malicious Python text at the start of the file was discovered in the pickle files that were taken out of the aforementioned PyTorch archives. A standard platform-aware reverse shell that connects to a hard-coded IP address served as the malicious payload in both instances. The method, which has been called nullifAI, entails blatant attempts to circumvent the protections already in place to detect malicious models read more about Malicious ML Models on Hugging Face Leverage Broken Pickle Format to Evade Detection. Get up to date on the latest cybers...