• News/
  • https://www.darkreading.com/cyber-risk/open-source-ai-models-pose-risks-of-malicious-code-vulnerabilities

Open Source AI Models: Perfect Storm for Malicious Code, Vulnerabilities

Dark Reading
·
Robert Lemos
·
Published Feb 14, 2025
·
Updated

Attackers are finding more and more ways to post malicious projects to Hugging Face and other repositories for open source artificial intelligence (AI) models, while dodging the sites' security checks. The escalating problem underscores the need for companies pursuing internal AI projects to have robust mechanisms to detect security flaws and malicious code within their supply chains. Hugging Face's automated checks, for example, recently failed to detect malicious code in two AI models hosted on the repository, according to a Feb. 3 analysis published by software supply chain security firm ReversingLabs. The threat actor used a common vector — data files using the Pickle format — with a new technique, dubbed "NullifAI," to evade detection. While the attacks appeared to be proofs-of-concept, their success in being hosted with a "No issue" tag shows that companies should not rely on Hugging Face's and other repositories' safety checks for their own security, says Tomislav Pericin, chief software architect at ReversingLabs. "You have this public repository where any developer or machine learning expert can host their own stuff, and obviously malicious actors abuse that," he says. "Depending on the ecosystem, the vector is going to be slightly different, but the idea is the same: Someone's going to host a malicious version of a thing and hope for you to inadvertently install it." Companies are quickly adopting AI, and the majority are also establishing internal projects using op...

Read full article

Affected Software

5 affected components
Hugging Face repository
Hugging Face PickleScan
EleutherAI Safetensors
Stability AI Safetensors
Hugging Face AI models
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the security risks associated with open-source AI models, particularly the threat of malicious code and vulnerabilities.

2

What security implications are discussed in the article?

The article highlights how attackers are exploiting open-source AI repositories to introduce harmful projects that can evade security checks.

3

What platforms are mentioned as being affected by these risks?

Hugging Face and its related projects, including Hugging Face repository and Hugging Face PickleScan, are specifically mentioned as being targeted.

4

Which specific products or software are recognized as vulnerable?

The article identifies Hugging Face AI models, Hugging Face PickleScan, and EleutherAI and Stability AI Safetensors as susceptible to potential malicious use.

5

How are attackers circumventing security measures in open-source AI repositories?

Attackers are finding ways to post malicious projects on platforms like Hugging Face while avoiding detection by existing security protocols.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203