Downloads · 30 days
0
Spoko-dev/huntr-mfv-dl4j-normalizer-reflection
huntr-mfv-dl4j-normalizer-reflection is a machine learning model from Spoko-dev. Use it for the machine learning task on the model card, and read the license before you ship it in a product.
Security-research PoC for a huntr MFV submission. Not malware — the demonstrator only writes harmless /tmp markers, and is a stand-in for a victim-classpath gadget (full RCE is gadget-gated).
Downloads · 30 days
0
Access
Public
Updated Jul 10, 2026
Repo size
1.2 KB
Likes
0
Public
Click a slice to open those files.
.java4.9 KB · 48%
From the Hugging Face model README
Security-research PoC for a huntr MFV submission. Not malware — the demonstrator only writes harmless /tmp markers, and is a stand-in for a victim-classpath gadget (full RCE is gadget-gated).
malicious_model.zip carries a normalizer.bin with a CUSTOM header naming an attacker class. Loading it via the default ModelSerializer.restoreMultiLayerNetworkAndNormalizer(File,true) calls ND4JClassLoading.loadClassByName(name) = Class.forName(name, /*initialize=*/true) (static initializer runs) then Class.newInstance() (no-arg constructor runs) — both before the type is checked (CWE-470 unsafe reflection).
DL4J/ND4J 1.0.0-M2.1, JDK 17. Build the classpath from libs/ (via mvn dependency:copy-dependencies on the included pom.xml).
# compile the demonstrator + craft/load driver, then:
java -cp "out:libs/*" CraftAndLoad
# [EvilNormalizerStrategy] WROTE marker /tmp/huntr_r2_normalizer_staticinit
# [EvilNormalizerStrategy] WROTE marker /tmp/huntr_r2_normalizer_ctor
# restore threw ClassCastException (expected, AFTER the sinks fire)
Both the static initializer and the no-arg constructor execute during the load. Files: src/CraftAndLoad.java (craft+load), src/EvilNormalizerStrategy.java (demonstrator), pom.xml (exact vulnerable deps).