logo

CVE-2026-39987 update: How attackers weaponized marimo to deploy a blockchain botnet via HuggingFace

ID: f97ad140-decc-59f1-966d-cad129af7ad1

STIX ID: report--f97ad140-decc-59f1-966d-cad129af7ad1

Feed Name: Sysdig Blog

Threat Score
78/100

Date Published: 2026-04-15

Date Updated: 2026-05-01

...
...

Sysdig Threat Research observed active exploitation of marimo CVE-2026-39987 within days of disclosure, with multiple operators performing credential harvesting, reverse shells, DNS-based OOB confirmation, and lateral movement to PostgreSQL and Redis; one operator deployed a UPX-packed NKAbuse Go backdoor (kagent) hosted on a typosquatted HuggingFace Space, and the report provides malware hashes, IOCs, detection rules, and remediation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.