Model and package supply chain
Risks in the models, weights, datasets and packages that AI systems are built from, including malicious uploads and unsafe file formats.
- All items
- 84
- Last 90 days
- 16
- Change
- -57%vs 37 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 0 |
| Jun 2025 | 0 |
| Jul 2025 | 1 |
| Aug 2025 | 0 |
| Sep 2025 | 0 |
| Oct 2025 | 0 |
| Nov 2025 | 0 |
| Dec 2025 | 2 |
| Jan 2026 | 1 |
| Feb 2026 | 8 |
| Mar 2026 | 13 |
| Apr 2026 | 5 |
| May 2026 | 18 |
| Jun 2026 | 10 |
| Jul 2026 | 8 |
| Aug 2026 | 5 |
| Sep 2026 | 6 |
| Oct 2026 | 1 |
84 items
CVE-2025-71340: picklescan fails to detect malicious pickle files invoking runcode in __reduce__
Jun 25, 2026HighVulnerabilitySecurityCVE-2025-71340picklescan through 0.0.26 fails to detect malicious pickle files that invoke idlelib.pyshell.ModifiedInterpreter.runcode in __reduce__ methods. Attackers can embed undetected code that runs arbitrary commands when the file is loaded via pickle.load(), enabling supply chain attacks on PyTorch models and saved Python objects.
Fix: This is fixed in version 0.0.30.
NVD/CVE DatabaseMicrosoft links Mastra AI supply chain attack to North Korean hackers
Jun 20, 2026MediumNewsSecurityIndustryMicrosoft attributes a Mastra AI npm supply chain attack, which compromised more than 140 packages in the @mastra scope, to the North Korean state actor Sapphire Sleet, also known as BlueNoroff. The attackers hijacked the npm maintainer account "ehindero" and published malicious updates that injected a typosquat dependency, "easy-day-js", which ran a postinstall hook to deploy a cross-platform information stealer targeting credentials and crypto wallets.
BleepingComputerGHSA-q8gq-377p-jq3r: vLLM: Security Check Bypass via assert Statement in Activation Function Loading Allows Arbitrary Code Execution
Jun 16, 2026HighVulnerabilitySecurityCVE-2026-41523An assert-based security check in vLLM's activation function loading, at vllm/model_executor/layers/pooler/activations.py:48, restricts which functions can be loaded from a HuggingFace model's config.json. When vLLM runs in Python optimized mode (python -O or PYTHONOPTIMIZE=1), Python strips the assert, so an attacker-published malicious model can pass an arbitrary function_name to resolve_obj_by_qualname() and execute code during model initialization. The attack requires the victim to load the malicious model and the model to use a cross-encoder architecture.
Fix: Suggested fix: replace the assert with an explicit conditional raise: if not function_name.startswith("torch.nn.modules."): raise ValueError("Loading of activation functions is restricted to torch.nn.modules for security reasons"). The source text ends mid-sentence at "A fix for this", so no released fixed version is stated.
Hugging Face Security AdvisoriesPickle in the Middle – Hijacking Vertex AI Model Uploads for Cross-Tenant RCE
Jun 16, 2026MediumNewsSecurityIndustryUnit 42 researchers disclosed a vulnerability in the Google Cloud Vertex AI Python SDK (google-cloud-aiplatform) that allows remote code execution in a victim's Vertex AI serving infrastructure. The flaw stems from a predictable default staging bucket name, combined with a missing ownership check, enabling bucket squatting. The issue affected versions 1.139.0 and 1.140.0, and Google fixed it in v1.148.0, released April 15, 2026.
Fix: Google completed the fixes in v1.148.0, released April 15, 2026. Developers are recommended to upgrade to fixed versions of the SDK.
Palo Alto Unit 42Meet Hades: The malware that lies to AI security agents
Jun 9, 2026MediumNewsSecurityIndustryThe Hades Campaign, discovered by StepSecurity researchers and described as the latest evolution of the Miasma threat actor, is a supply chain compromise targeting Python developer environments. It runs when infected packages are imported, using the Bun runtime to execute multi-layer payloads that harvest credentials, scrape Linux, macOS and Windows memory, and spread as a self-replicating worm. The malware also embeds a text block that tricks LLM-based scanners into classifying the malicious package as clean.
CSO OnlineICYMI: May 2026 @AWS Security
Jun 8, 2026InfoNewsIndustryPolicyThe AWS Security Blog's May 2026 monthly digest lists recent posts on AI security, network protection, identity management, compliance frameworks and supply chain security. It links to guidance on securing agentic AI workflows, filtering network traffic by category, and defending against supply chain attacks. The page is a list of posts and their publication dates rather than a single security event.
AWS Security BlogGHSA-fgcw-684q-jj6r: huggingface/transformers: Arbitrary Code Execution During Model Initialization in the LightGlue Model Loading Path
Jun 3, 2026HighVulnerabilitySecurityCVE-2026-5241A flaw in the LightGlue model loading path of huggingface/transformers 5.2.0 lets an attacker-controlled model repository run arbitrary code during model initialization. The `trust_remote_code` value, meant to block remote code, is overridden by the `trust_remote_code` setting read from the untrusted `config.json` and passed into nested `AutoConfig.from_pretrained()` calls. Code runs even when the victim calls `AutoModel.from_pretrained()` with `trust_remote_code=False`. The source rates the risk as high for inference servers, notebooks, CI/CD pipelines and evaluation workers, citing possible credential theft, lateral movement and persistence.
GitHub Advisory DatabaseCVE-2026-47117: OpenMed remote code execution in PII privacy-filter model loading
Jun 2, 2026CriticalVulnerabilitySecurityCVE-2026-47117CVE-2026-47117 affects OpenMed before 1.5.2, where the PII privacy-filter model loading path contains a remote code execution flaw. The privacy-filter dispatcher applied broad substring matching to the user-supplied model_name parameter, so a value such as attacker/foo-privacy-filter-bar routed to a path that loads Hugging Face models with trust_remote_code=True. An unauthenticated attacker who supplies a malicious model repository with custom code referenced through auto_map in config.json or tokenizer_config.json gets that code imported and executed with the privileges of the OpenMed service process.
NVD/CVE DatabaseAttack targeting OpenAI Codex users exposes AI software supply chain risks
Jun 2, 2026MediumNewsSecurityIndustryA malicious npm package named codexui-android, posing as a remote user interface for OpenAI Codex, exfiltrated developer authentication tokens, according to researchers at Aikido. The code that stole the tokens appeared only in the published npm version, not in the project's public GitHub repository, and the package had around 27,000 weekly downloads. A companion Android app automatically pulled and executed the npm package at runtime, and the stolen refresh tokens do not expire, giving attackers persistent access.
CSO OnlineOpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain Attack
Jun 1, 2026MediumNewsSecurityIndustryResearchers at Aikido Security disclosed a malicious campaign in which the npm package codexui-android, a remote web UI for OpenAI Codex with over 29,000 weekly downloads, was altered about a month after publication to read ~/.codex/auth.json and send its contents to sentry.anyclaw[.]store, a server masquerading as Sentry. The stolen access_token, refresh_token, id_token and account ID give persistent access, since the refresh_token does not expire. The same exfiltration chain appears in Android apps linked to the developer BrutalStrike, including one with over 50,000 downloads.
The Hacker NewsMalicious npm Package Stole Files From Claude AI User Directory via GitHub
May 27, 2026MediumNewsSecurityIndustryOX Security reported a malicious npm package named "mouse5212-super-formatter" that poses as an internal "archive deployment sync" utility. During the postinstall stage it authenticates to GitHub, using a token from the victim's environment or a hard-coded fallback, and recursively uploads every file from "/mnt/user-data", the directory Anthropic's Claude uses for uploads and outputs, to a threat actor-controlled GitHub account. The package is estimated to have been downloaded 676 times, though the number of actual installs is unclear.
The Hacker News‘SymJack’ Attack Turns AI Coding Agents Into Supply Chain Attack Delivery Systems
May 27, 2026MediumNewsSecurityIndustryAdversa AI describes SymJack, an attack that uses a malicious repository to turn AI coding agents into delivery mechanisms for supply chain attacks. A malicious symlink, renamed to look innocuous, is used with a cp command to plant a payload in the agent's configuration, registering a malicious MCP server whose startup command runs attacker code as the user on the next restart. Adversa reports the method worked in all five coding agents it tested, including Claude Code, Gemini CLI, Cursor Agent CLI, Grok Build CLI and GitHub's Copilot CLI.
Fix: Anthropic quietly hardened Claude Code, which now resolves symlinks before asking for approval and shows the real destination path in the prompt. The article calls this a good start and suggests other coding agents could implement similar prompts.
SecurityWeekGHSA-xmpw-2vmm-p4p6: Malicious code in guardrails-ai 0.10.1 (supply chain compromise)
May 19, 2026CriticalVulnerabilitySecurityIndustryCVE-2026-45758A malicious version, guardrails-ai 0.10.1, was published to PyPI on May 11, 2026 at approximately 6:00 PM Pacific by an attacker. Anyone who installed guardrails-ai==0.10.1 from PyPI that day is affected, and PyPI quarantined the repository after researchers identified the package within about 2 hours. The maintainers report no requests to Guardrails AI infrastructure from the malicious version and no evidence of user data exfiltration through their systems.
Fix: Downgrade to guardrails-ai==0.10.0, which is unaffected, since no patched version above 0.10.1 is available yet. While the PyPI quarantine is active, install from GitHub with pip install git+https://github.com/guardrails-ai/guardrails.git@v0.10.0. If 0.10.1 was installed, treat the host as potentially compromised, rotate any credentials accessible from it (GitHub PATs, cloud provider keys, package registry tokens, API keys), and audit the GitHub account for unauthorized workflows or repositories. Snowglobe and Guardrails Hub API keys will be invalidated at 2:00 PM Pacific on May 13, 2026, so rotate them before then.
GitHub Advisory DatabaseTanStack Supply Chain Attack Hits Two OpenAI Employee Devices, Forces macOS Updates
May 15, 2026MediumNewsSecurityIndustryOpenAI disclosed that two employee devices were affected by the Mini Shai-Hulud supply chain attack on TanStack. OpenAI says no user data, production systems, or intellectual property were compromised or modified without authorization, though limited credential material was transferred from internal source code repositories. Because those repositories held signing certificates for iOS, macOS, and Windows products, OpenAI revoked them and issued new ones, requiring macOS users of ChatGPT Desktop, Codex App, Codex CLI, and Atlas to update before the old certificate is revoked on June 12, 2026.
Fix: Revoked the compromised code-signing certificates and issued new ones. macOS users of ChatGPT Desktop, Codex App, Codex CLI, and Atlas must update to the latest versions before the previous certificate is revoked on June 12, 2026. Users do not need to take action for Windows and iOS apps.
The Hacker NewsOpenAI Hit by TanStack Supply Chain Attack
May 15, 2026MediumNewsSecurityIndustryOpenAI disclosed that a TanStack supply chain attack by the TeamPCP group exfiltrated limited credential material from internal source code repositories after two employee devices were infected. OpenAI says no customer data or intellectual property was affected, and it has rotated credentials, revoked user sessions and temporarily restricted code-deployment workflows. The company is also revoking code-signing certificates for its iOS, macOS, Windows and Android products, and macOS users must update their apps by June 12, 2026.
Fix: OpenAI rotated credentials across all affected repositories, revoked user sessions, and temporarily restricted code-deployment workflows. It is revoking its code-signing certificates and re-signing all applications, and macOS users must update their OpenAI apps to the latest versions by June 12, 2026. It is also coordinating with platform providers to stop new notarizations using the stolen certificates.
SecurityWeekOpenAI confirms security breach in TanStack supply chain attack
May 14, 2026MediumNewsSecurityIndustryOpenAI says two employees' devices were breached in the TanStack supply chain attack, which the company links to the Mini Shai-Hulud campaign by the TeamPCP extortion gang. Activity in a limited subset of internal source code repositories included credential-focused exfiltration, and OpenAI says no customer data, production systems or deployed software were affected. The company is rotating code-signing certificates as a precaution.
Fix: OpenAI isolated affected systems and accounts, revoked sessions, rotated credentials across affected repositories, and temporarily restricted deployment workflows. macOS users must update OpenAI desktop applications before June 12, 2026, because applications signed with the older certificates may not launch or receive updates. Windows and iOS users do not need to take action.
BleepingComputerOur response to the TanStack npm supply chain attack
May 12, 2026LowIncidentSecurityIndustryOpenAI reports that two employee devices were affected by the Mini Shai-Hulud attack, which used a compromised TanStack npm package. The company says the activity led to limited credential exfiltration from a subset of internal source code repositories, and it found no evidence of customer data access, intellectual property compromise, or altered software.
Fix: OpenAI says it isolated impacted systems and identities, revoked user sessions, rotated all credentials across impacted repositories, and temporarily restricted code-deployment workflows. It is rotating code-signing certificates as a precaution, is stopping new notarizations with the previous certificates, and will fully revoke the certificate on June 12, 2026, after which macOS will block new downloads and launches of apps signed with it. macOS users will need to update their applications. The company also cites package manager configurations with minimumReleaseAge and additional provenance validation tools as controls it deployed, noting the two affected devices lacked them.
OpenAI BlogCVE-2026-31239: mamba language model framework insecure deserialization when loading models
May 12, 2026HighVulnerabilitySecurityCVE-2026-31239The mamba language model framework through 2.2.6 is affected by insecure deserialization (CWE-502) when loading pre-trained models from HuggingFace Hub. The MambaLMHeadModel.from_pretrained() method calls torch.load() on pytorch_model.bin without setting weights_only=True, so arbitrary Python objects can be deserialized via the pickle module. An attacker who publishes a malicious model repository can execute arbitrary code on a victim's system, in the context of the mamba process, when the victim loads a model from it.
NVD/CVE DatabaseCVE-2026-31232: CosyVoice insecure deserialization in model loading via torch.load
May 12, 2026HighVulnerabilitySecurityCVE-2026-31232CVE-2026-31232 affects the CosyVoice project through commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) and is classified as CWE-502. The model loading process calls torch.load() without weights_only=True when reading .pt files from a directory passed via --model_dir, so arbitrary Python objects can be deserialized through Pickle. An attacker who supplies a crafted model directory can trigger remote code execution on a victim who loads it through the CosyVoice web interface.
NVD/CVE DatabaseCVE-2026-31229: The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains an insecure deserialization vulnerability (CWE-502) in…
May 12, 2026HighVulnerabilitySecurityCVE-2026-31229The Adversarial Robustness Toolbox (ART) through 1.20.1 contains an insecure deserialization flaw (CWE-502) in its Kubeflow component's model loading. During robustness evaluation, model weights loaded from a file such as model.pt use torch.load() without weights_only=True, which permits Pickle deserialization of arbitrary Python objects. An attacker who uploads a crafted model file to object storage referenced by the pipeline, or who controls the model_id parameter to point to such a file, can achieve remote code execution when the pipeline loads the model.
NVD/CVE Database
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.