Postmortem · Model Supply Chain · Ongoing
Downloading a model can run code. Pickle-based model files execute arbitrary Python on load — and attackers have shipped backdoored models to public hubs. Here is the record and the defenses.
Private AI on Kubernetes almost always pulls open-weight models from public hubs. If those models are pickle-serialized, loading one can execute arbitrary code inside your inference Pod — and malicious models have repeatedly reached the Hugging Face Hub.
This is a recurring supply-chain class rather than a single CVE. PyTorch’s default save format wraps weights in Python’s pickle module, and pickle executes arbitrary Python on load: an attacker overrides __reduce__ on a custom class so that torch.load() runs a payload as a side effect of "deserializing" the model. Researchers have repeatedly found backdoored models on the Hugging Face Hub — ReversingLabs’ "nullifAI" campaign (February 2025) shipped reverse shells in pickle models and evaded the platform’s picklescan by using 7z archives and intentionally malformed pickles that picklescan failed to parse but Python still executed; JFrog flagged 100+ malicious models in early 2025; and earlier 2024 rounds found the same pattern. Hugging Face removed flagged models quickly, but the lesson stands: a model file is executable code. The record and defenses are below.
What We Offer
From daily job support to emergency production fixes, proxy interview guidance, and interview coaching — we have the expert for your specific need.
Live expert help during your working hours — running LLM inference (vLLM, KServe, Dynamo), agent runtimes and sandboxes, GPU scheduling, autoscaling, RAG pipelines, and daily platform deliverables on your real cluster so you always hit your deadlines.
On-call firefighting for live incidents — GPU Pods stuck Pending, CUDA/OOMKilled crashes, vLLM out-of-memory, high TTFT, model-loading failures, autoscaling that will not scale, agent loops, MCP authorization errors, and RAG/vector-DB latency — with an engineer on the call.
Kubernetes AI proxy interview assistance, profile positioning, and candidate marketing for Platform Engineer, AI Infrastructure Engineer, GPU Infrastructure Engineer, MLOps/LLMOps, and SRE roles — real-time interview guidance, recruiter readiness, and profile visibility.
Real Situations
These are the real-world situations our experts resolve every day — for job support and interview assistance.
Global Reach
Real-time Kubernetes AI infrastructure support for engineers across USA, Canada, UK, Ireland, Germany, Netherlands, Switzerland, Australia, New Zealand, Singapore, UAE, and worldwide.
Available across US, Canada, UK, European, Australian, and Asia-Pacific business hours — and 24/7 for production incidents.
Join 1000+ developers who resolved their job challenges and cleared interviews with real-time expert support.
Expert Help Available
Need real-time IT job support or interview help? Our experts are available 24/7 — USA, Canada, UK, Europe & worldwide.
FAQ
Everything you need to know before getting started with job support or interview assistance.
Ask on WhatsAppReversingLabs’ "nullifAI" research on malicious ML models on Hugging Face, JFrog’s findings on malicious models, and Hugging Face’s own guidance on pickle risks and safetensors. Verify current platform protections before relying on them.
Read the ReversingLabs malicious-model research (nullifAI)Get Started Today
In-house Kubernetes, GPU, and AI-infrastructure security engineers available same-day — safe production patching, blast-radius review, and hardening against this class of risk. Talk to ProxyTechSupport on WhatsApp now.
Proxy Tech Support provides interview preparation, technical guidance, and job support services. All services are advisory and educational in nature.