IncidentMalicious PyTorch Model Escaped Detection for Weeks
In February 2024, JFrog researchers discovered a weaponized PyTorch model on Hugging Face that opened a reverse shell on any system that loaded it. The model sat in a public repository, unsigned and u














