ComfyUI statement on the Ultralytics crypto miner situation.
Blog post from Comfy
In December 2024, ComfyUI issued a statement regarding the discovery of a crypto miner in versions v8.3.41 and v8.3.42 of the ultralytics pip package, which only affects Mac and Linux users, likely targeting servers rather than regular users. Windows users are not impacted. The compromised package, which is a dependency for popular custom nodes like the ComfyUI-Impact-Pack, involves the download and execution of a binary miner on affected systems. Users can determine their exposure by updating the ComfyUI manager, which now checks for and warns about these vulnerabilities. To mitigate the impact, users should kill the relevant process, delete the file, and remove the compromised package versions. In response, ComfyUI has updated its manager to flag these issues and pin the ultralytics version to 8.3.40, considered safe, while planning future sandboxing protections for their desktop app. The team expressed gratitude for the community's prompt reaction to this security issue and offered various channels for further inquiries.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.