CoolFace
Modelpublic

xiaoyaoes/modelscan-nested-pickle-bypass

sourceHugging Facemitupdated 3mo agoView on Hugging Face
0likes
Model Card

ModelScan Nested Pickle Bypass

A novel technique that hides malicious pickled objects inside opaque BINBYTES blocks. ModelScan only inspects outer-layer GLOBAL opcodes, so the inner pickle (containing os.system, subprocess, etc.) is never scanned.

Bypass GLOBALs (what ModelScan sees)

  • importlib.import_module — NOT in unsafe_globals
  • operator.methodcaller — NOT in unsafe_globals

Hidden GLOBALs (inside BINBYTES, never inspected)

  • os.system — full RCE
  • (or any other blocked module)

Verification

bash
modelscan -p exploit_nested.joblib
# -> "No issues found!"

PoC Size

177 bytes

Format

Joblib (pickle-based, $4,000 MFV tier)