Supply-chain threat intelligence

Incident detail

criticalpypi·credential theft·github

Malicious code in yolov8mini (PyPI)

yolov8mini

Risk score

92

AI summary

Indexed incident for yolov8mini (pypi).

Description

On importing the module, there is an automated start of a Telegram bot capable of exfiltrating passwords from browsers, executing arbitrary commands and so on. While the description states it's a monitoring tool, the automated start, capabilities targeting secret values suggest malicious intentions.


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2025-03-yolov8mini

Reasons (based on the campaign):

  • infostealer

  • exfiltration-generic

  • dependency-confusion

  • exfiltration-browser-data

  • The package contains code to execute remote commands (probably limited to a specific set) on the victim's machine.


Credit: OpenSSF (source)

Technical details

Indicators

  • ghsa
    95%

Timeline

  1. Advisory published
  2. Indexed by ThreatPkg

Related incidents