Is ultralytics safe?
Confirmed malicious. Do not install it, and remove it where it has been installed.
Do not install this package
CRITICALanalyst verifiedworkflow_injection_pr_target. Confirmed 2026-05-11, verified by a CyberXYZ analyst.
GAP-1: ultralytics PyPI compromise 2024-12-04 — workflowinjection via pullrequesttarget. v8.3.41-45 contained XMRig crypto miner. See vendorincidents id=45.
- Malicious
- 8.3.41, 8.3.42, 8.3.43, 8.3.44, 8.3.45
- Clean
- none confirmed
Remove it from every machine and lockfile it reached. Treat any credentials, tokens and SSH keys present on those machines as exposed and rotate them. Check CI runners and container images that installed it.
pip uninstall ultralytics
7 published models
1 declared · 7 observed · 0 inferred
| Model | Evidence |
|---|---|
| Anzhc/Anzhcs_YOLOs | observed |
| Bingsu/adetailer | observed |
7 published AI models are associated with this package: 1 name it in a requirements or pyproject file, 7 load it or import it directly, and 0 are inferred from the runtime stack their declared library pulls in. Only 1 state a version requirement, so this is not a count of affected models.
Checked 2026-10-03 at 04:20 UTC. Updated continuously from NVD, GHSA, OSV and CNA feeds.