Description

China’s National Cybersecurity Notification Center has issued an urgent warning about serious security flaws in ComfyUI, a widely used image-generation framework for large-scale AI models. These flaws are currently being exploited by hackers deploying a sophisticated backdoor known as Pickai. First detected by XLab’s Cyber Threat Insight and Analysis System (CTIA) on March 17, 2025, Pickai has already compromised at least 695 servers globally. The attackers leveraged vulnerabilities in ComfyUI to spread malicious ELF executables disguised as benign files like config.json and tmux.conf, targeting organizations that deploy AI models privately across industries. Coded in C++, Pickai is a stealthy, lightweight malware that facilitates data theft, remote command execution, and reverse shell access. Despite lacking encryption, it ensures persistence through multiple tactics—anti-debugging, process name spoofing (e.g., kworker, auditlogd), redundant system path copies, and a rotating set of hardcoded command-and-control (C2) servers. Notably, XLab registered an unclaimed C2 domain—h67t48ehfth8e.com—to monitor the scale of the attack, uncovering widespread infections in countries including Germany, the U.S., and China. To maintain long-term control, attackers have now shifted to a new domain—historyandresearch.com—with a five-year lease. Alarmingly, Pickai samples were found hosted on the official site of Rubick.ai, a commercial AI platform serving over 200 major e-commerce brands, potentially making it a key vector in a broader supply chain attack. Despite XLab’s disclosure attempts, Rubick.ai has not responded, leaving the threat active. With its use of XOR encryption (key: 0xAF), persistent evasion techniques, and evolving C2 infrastructure, Pickai poses a serious risk to AI infrastructures. Network administrators are urged to perform deep forensic scans and eliminate all traces to prevent reinfection. XLab is actively tracking the threat and urges the cybersecurity community to collaborate in sharing intelligence to help eliminate it.