Downloads · 30 days
0
TESTforge42/scanner-bypass-npz-int-desync
scanner-bypass-npz-int-desync is a machine learning model from TESTforge42. Use it for the machine learning task on the model card, and read the license before you ship it in a product. The card lists the license as apache-2.0.
Benign PoC for the huntr Model File Format program. Payload writes only a nonce marker — no real harm. A NumPy .npz is a ZIP of .npy members. Both scanners RECURSE into the .npz and scan each member (positive control:…
Downloads · 30 days
0
Access
Public
Updated Jul 24, 2026
Repo size
335 B
Likes
0
Public
Click a slice to open those files.
Other1.5 KB · 50%
From the Hugging Face model README
Benign PoC for the huntr Model File Format program. Payload writes only a nonce marker — no real harm.
A NumPy .npz is a ZIP of .npy members. Both scanners RECURSE into the .npz and scan each member (positive control: a plain malicious object-.npy inside the .npz is CAUGHT by BOTH). This PoC's object-dtype member carries the INT-opcode desync prefix "I0x10\n": genops parses base-10 and aborts before the payload, while np.load(..., allow_pickle=True)[member] parses "0x10" base-0 and executes the embedded reduce payload. Distinct ZIP-recursion code path + real npz member-access loader ($1500 non-pickle tier).
import numpy as np
z = np.load("model.npz", allow_pickle=True); z[z.files[0]] # fires the benign marker
picklescan -p model.npz # exit 0
modelscan -p model.npz # no issue