Downloads · 30 days
0
TESTforge42/scanner-bypass-legacy-pt-desync
scanner-bypass-legacy-pt-desync is a machine learning model from TESTforge42. Use it for the machine learning task on the model card, and read the license before you ship it in a product. The card lists the license as apache-2.0.
Benign PoC for the huntr Model File Format program. Payload writes only a nonce marker — no real harm. The legacy torch serialization (torch.save(..., usenewzipfileserialization=False)) is the format most pre-safetens…
Downloads · 30 days
0
Access
Public
Updated Jul 24, 2026
Repo size
264 B
Likes
0
Public
Click a slice to open those files.
.md1.6 KB · 47%
From the Hugging Face model README
Benign PoC for the huntr Model File Format program. Payload writes only a nonce marker — no real harm.
The legacy torch serialization (torch.save(..., _use_new_zipfile_serialization=False)) is the format most pre-safetensors HF pytorch_model.bin checkpoints ship in: a flat concatenation of pickles (magic, protocol, sys_info, then the main object pickle). ModelScan's scan_pytorch calls scan_pickle_bytes(multiple_pickles=False) — it scans ONLY the protocol pickle and NEVER the main object pickle, so a plain malicious legacy .bin already evades it. picklescan's legacy branch loops for _ in range(5): scan_pickle_bytes(...) and RESUMES after a genops error; prepending 6 int-opcode-desync pickles (I0x10\n) exhausts all 5 iterations so the real main pickle falls beyond the scan window and its GLOBAL is never seen (picklescan exit 0). torch._legacy_load reads the whole stream with the C unpickler: leading junk ints are discarded and the main object's reduce fires -> arbitrary code execution at load. Distinct scanner code path (flat 5-pickle loop) + distinct loader (_legacy_load) from the .pt-ZIP variant.
import torch
torch.load("pytorch_model.bin", weights_only=False) # fires the benign marker