Python libraries have been infected with falsified metadata in artificial intelligence models, which can execute malicious code when loaded. The NeMo, Uni2TS , and FlexTok, used in Hugging Face models for Artificial Intelligence (AI) and Machine Learning (ML), have serious vulnerabilities. As researchers from Palo Alto Networks, criminals can exploit them to hide malicious code in the metadata.
See also: New VVS Stealer targets Discord accounts via Python

Once introduced, the code is automatically triggered when a file with the falsified metadata is loaded. Technically, the vulnerabilities mainly concern the `instantiate()` function of the Hydra library. This is a Python library used by all three AI and ML libraries. Hydra is maintained by Facebook's parent company, Meta, and is often used as a configuration management tool for machine learning projects.
Although the vulnerabilities are widespread, security experts have yet to find any exploits in the wild. However, they warn that attackers still have plenty of opportunities to exploit them. Curtis Carmony, a malware researcher at Unit 42, explains that it's common for developers to create their own variations of advanced models with different settings and quantifications, often from researchers outside of recognized institutions.
See also: APT36 used Python ELF malware against the Indian government

Attackers could simply modify an existing, widely used model that offers a real or perceived advantage and add malicious metadata. The situation is exacerbated by the fact that Hugging Face does not make metadata as easily accessible as other files, and files using Safetensors or the NeMo format are not marked as potentially unsafe.
Another factor is that, according to Unit 42, over 100 Python libraries are used in Hugging Face for AI and ML models — and nearly 50 of them use Hydra. Carmony explains that these formats are not insecure in themselves, but “the code that uses them offers a very large attack surface.”
Technically, this is related to how NeMo, Uni2TS, and FlexTok use the `hydra.utils.instantiate()` function to load configurations from model metadata. This allows for remote code execution (RCE). The creators or maintainers of these libraries seem to have overlooked something, as Unit 42 explains: `instantiate()` accepts not only the name of the classes to be instantiated, but also the name of any called function and passes it the specified arguments.
See also: Domain hijacking risk from old Python Bootstrap Scripts

This has serious consequences, as once an attacker uses built-in Python functions like eval() and os.system(), they can more easily extract code. Meta has updated the Hydra documentation and now warns that RCE is possible when `instantiate()` is used.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
