supply chain / transformers

HuggingFace Transformers

registryPyPI
package nametransformers
maintainerHugging Face

HuggingFace Transformers is the de facto standard library for loading, fine-tuning, and running pretrained language models from the Hugging Face Hub. It supports thousands of models across PyTorch, TensorFlow, and JAX. Production ML pipelines that serve models locally rather than via API depend on this package.

api usage

Checking HuggingFace Transformers

transformers 4.44.0 is a clean, monitored version with no known supply chain compromise. The example response returns supply_chain_monitored: true and compromised: false with an empty sources array.

bash
curl "https://api.attestd.io/v1/check?product=transformers&version=4.44.0" \
  -H "Authorization: Bearer YOUR_API_KEY"
example response
json
{
  "product": "transformers",
  "version": "4.44.0",
  "supported": true,
  "risk_state": "none",
  "risk_factors": [],
  "actively_exploited": false,
  "remote_exploitable": false,
  "authentication_required": false,
  "patch_available": false,
  "fixed_version": null,
  "confidence": 0.9,
  "cve_ids": [],
  "cves": null,
  "max_epss": null,
  "typosquat": null,
  "supply_chain_monitored": true,
  "supply_chain": {
    "compromised": false,
    "sources": [],
    "malware_type": null,
    "description": null,
    "advisory_url": null,
    "compromised_at": null,
    "removed_at": null
  },
  "last_updated": "2026-05-01T00:00:00Z"
}
attack surface

Why this package is monitored

Hugging Face Transformers loads Hub artifacts that can include executable code in model files, configs, and tokenizer definitions. A malicious library build can hijack that load path and run attacker code before inference starts.

Attestd monitors transformers using the following detection sources:

registry

Manually curated advisories in the Attestd registry, verified by a human analyst. Confidence 1.0.

osv

OSV.dev malicious-package advisories with IDs prefixed MAL-. Confidence 0.95.

pypi_yank

Versions yanked on PyPI with a security-related yanked_reason annotation. Confidence 0.80.

related