YAML Metadata Warning:empty or missing yaml metadata in repo card
Check out the documentation for more information.
Security PoC β DeepLearning4J NormalizerSerializer unsafe reflection (huntr MFV)
Security-research PoC for a huntr MFV submission. Not malware β the demonstrator only writes harmless /tmp markers, and is a stand-in for a victim-classpath gadget (full RCE is gadget-gated).
malicious_model.zip carries a normalizer.bin with a CUSTOM header naming an attacker class. Loading it via the default ModelSerializer.restoreMultiLayerNetworkAndNormalizer(File,true) calls ND4JClassLoading.loadClassByName(name) = Class.forName(name, /*initialize=*/true) (static initializer runs) then Class.newInstance() (no-arg constructor runs) β both before the type is checked (CWE-470 unsafe reflection).
Environment
DL4J/ND4J 1.0.0-M2.1, JDK 17. Build the classpath from libs/ (via mvn dependency:copy-dependencies on the included pom.xml).
Reproduce
# compile the demonstrator + craft/load driver, then:
java -cp "out:libs/*" CraftAndLoad
# [EvilNormalizerStrategy] WROTE marker /tmp/huntr_r2_normalizer_staticinit
# [EvilNormalizerStrategy] WROTE marker /tmp/huntr_r2_normalizer_ctor
# restore threw ClassCastException (expected, AFTER the sinks fire)
Both the static initializer and the no-arg constructor execute during the load. Files: src/CraftAndLoad.java (craft+load), src/EvilNormalizerStrategy.java (demonstrator), pom.xml (exact vulnerable deps).