# ultralytics

Published articles for ultralytics.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Announcing Chainguard Libraries for Python: Malware-Resistant Dependencies Built Securely from Source

DevFeed: [Announcing Chainguard Libraries for Python: Malware-Resistant Dependencies Built Securely from Source](<https://devfeed.tech/articles/announcing-chainguard-libraries-for-python-malware-resistant-dependencies-built-securely-from-source-12880.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/announcing-chainguard-libraries-for-python-malware-resistant-dependencies-built-securely-from-source>)

Published: 2025-05-14T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard libraries for python](<https://devfeed.tech/topics/chainguard-libraries-for-python.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Python](<https://devfeed.tech/topics/python.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [chainguard libraries](<https://devfeed.tech/topics/chainguard-libraries.md>)

Tags: [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [chainguard-libraries-for-python](<https://devfeed.tech/tags/chainguard-libraries-for-python.md>), [chibbies](<https://devfeed.tech/tags/chibbies.md>), [malware](<https://devfeed.tech/tags/malware.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [python](<https://devfeed.tech/tags/python.md>), [python-libraries](<https://devfeed.tech/tags/python-libraries.md>), [pytorch](<https://devfeed.tech/tags/pytorch.md>), [safe-source-for-open-source](<https://devfeed.tech/tags/safe-source-for-open-source.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [ultralytics](<https://devfeed.tech/tags/ultralytics.md>)

### AI overview

Chainguard announces the early access release of Chainguard Libraries for Python, a malware-resistant index of Python dependencies built securely from source. It is intended to help application security and platform engineering teams address supply chain attacks during build and distribution, including risks from native dependencies and bundled operating system libraries. The libraries maintain compatibility across Chainguard OS, RHEL, Debian, and Ubuntu.

### Source excerpt

Chainguard Libraries for Python is an index of Python dependencies designed to protect users from malware attacks at the build and distribution stages.

## Ultralytics AI Pwn Request Supply Chain Attack

DevFeed: [Ultralytics AI Pwn Request Supply Chain Attack](<https://devfeed.tech/articles/ultralytics-ai-pwn-request-supply-chain-attack-8222.md>)

Original publisher: [Read original article](<https://snyk.io/blog/ultralytics-ai-pwn-request-supply-chain-attack/>)

Author: Stephen Thoemmes

Published: 2024-12-11T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Cryptocurrency](<https://devfeed.tech/topics/cryptocurrency.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [Google](<https://devfeed.tech/topics/google.md>), [comfyui](<https://devfeed.tech/topics/comfyui.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [comfyui](<https://devfeed.tech/tags/comfyui.md>), [cryptocurrency](<https://devfeed.tech/tags/cryptocurrency.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [github](<https://devfeed.tech/tags/github.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [google](<https://devfeed.tech/tags/google.md>), [malware](<https://devfeed.tech/tags/malware.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [pypi](<https://devfeed.tech/tags/pypi.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-container](<https://devfeed.tech/tags/snyk-container.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [ultralytics](<https://devfeed.tech/tags/ultralytics.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The article analyzes the two-phase Ultralytics supply chain attack in December 2024. Attackers published malicious PyPI versions containing cryptocurrency-mining malware, first through compromised GitHub Actions workflows and later by publishing directly to PyPI. The article presents the release timeline, detection signals such as unusual CPU usage and repository discrepancies, and guidance for detecting exposure and securing projects.

### Source excerpt

Discover the details of the Ultralytics AI supply chain attack, a sophisticated two-phase breach targeting PyPI releases and GitHub Actions with cryptocurrency mining malware. Learn how to detect exposure, secure your projects, and protect against future vulnerabilities using tools like Snyk.