Home / Companies / Comfy / Blog / Post Details
Content Deep Dive

ComfyUI statement on the Ultralytics crypto miner situation.

Blog post from Comfy

Post Details
Company
Date Published
Author
ComfyUI Blog
Word Count
435
Company Posts That Month
5
Language
English
Hacker News Points
-
Post removed?
No
Summary

In December 2024, ComfyUI issued a statement regarding the discovery of a crypto miner in versions v8.3.41 and v8.3.42 of the ultralytics pip package, which only affects Mac and Linux users, likely targeting servers rather than regular users. Windows users are not impacted. The compromised package, which is a dependency for popular custom nodes like the ComfyUI-Impact-Pack, involves the download and execution of a binary miner on affected systems. Users can determine their exposure by updating the ComfyUI manager, which now checks for and warns about these vulnerabilities. To mitigate the impact, users should kill the relevant process, delete the file, and remove the compromised package versions. In response, ComfyUI has updated its manager to flag these issues and pin the ultralytics version to 8.3.40, considered safe, while planning future sandboxing protections for their desktop app. The team expressed gratitude for the community's prompt reaction to this security issue and offered various channels for further inquiries.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.