Malicious ML Models on Hugging Face Leverage Broken Pickle Format to Evade Detection

Feb 8, 2025

Cybersecurity researchers have uncovered two malicious machine learning (ML) models on Hugging Face that leveraged an unusual technique of “broken” pickle files to evade detection.
“The pickle files extracted from the mentioned PyTorch archives revealed the malicious Python content at the beginning of the file,” ReversingLabs researcher Karlo Zanki said in a report shared with The Hacker News. “

Get Free Report & Network Analysis

Please check your email for the free report.