I'm mind blown you can compromise a release CI/CD system with two malicious branch names. Like how.
github.com/ultralytics/ultraly…
#Security #SupplyChainSecurity
Discrepancy between what's in GitHub and what's been published to PyPI for v8.3.41 · Issue #18027 · ultralytics/ultralytics
Bug Code in the published wheel 8.3.41 is not what's in GitHub and appears to invoke mining. Users of ultralytics who install 8.3.41 will unknowingly execute an xmrig miner. Examining the file util...GitHub