Downloads · 30 days
0
TESTforge42/scanner-bypass-npy-int-desync
scanner-bypass-npy-int-desync is a machine learning model from TESTforge42. Use it for the machine learning task on the model card, and read the license before you ship it in a product. The card lists the license as apache-2.0.
Benign security-research PoC for the huntr Model File Format program. Payload only writes a nonce marker (echo) — no real harm. A valid object-dtype NumPy .npy embeds a pickle stream that ModelScan scans via its numpy…
Downloads · 30 days
0
Access
Public
Updated Jul 24, 2026
Repo size
219 B
Likes
0
Public
Click a slice to open those files.
Other1.5 KB · 52%
From the Hugging Face model README
Benign security-research PoC for the huntr Model File Format program. Payload only writes a nonce marker (echo) — no real harm.
A valid object-dtype NumPy .npy embeds a pickle stream that ModelScan scans via its numpy-specific path (NumpyUnsafeOpScan) and picklescan via its numpy handling. The embedded pickle carries the INT-opcode desync prefix (I0x10\n): genops parses base-10 and aborts before the payload, while numpy.load(allow_pickle=True) parses 0x10 base-0 and executes the reduce payload. Defeats the numpy-SPECIFIC defence that CATCHES a plain malicious object .npy — a distinct code path and format ($1500 non-pickle tier).
import numpy as np
np.load("model.npy", allow_pickle=True) # fires the benign marker at load
picklescan -p model.npy # exit 0
modelscan -p model.npy # no issue