logo

Attackers Weaponize CVE-2026-39987 to Spread Blockchain-Based Backdoor Via Hugging Face

ID: 4a2c166e-2bc8-51c2-8b9a-a110261970a0

STIX ID: report--4a2c166e-2bc8-51c2-8b9a-a110261970a0

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-04-17

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A critical unauthenticated RCE (CVE-2026-39987) in the marimo Python notebook platform is being actively exploited to deploy a UPX-packed Go backdoor named kagent (a new NKAbuse variant) via a typosquatted Hugging Face Space; attackers conducted credential harvesting, stole AWS and API keys, pivoted to PostgreSQL/Redis instances, and used the decentralized NKN blockchain for resilient C2. Defenders are urged to update marimo to 0.23.0+, hunt for ~/.kagent artifacts and kagent service entries, rotate exposed credentials, block the delivery domain, and monitor for NKN relay patterns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.