Attackers Weaponize CVE-2026-39987 to Spread Blockchain-Based Backdoor Via Hugging Face
ID: 4a2c166e-2bc8-51c2-8b9a-a110261970a0
STIX ID: report--4a2c166e-2bc8-51c2-8b9a-a110261970a0
Feed Name: cybersecurityNews.com
A critical unauthenticated RCE (CVE-2026-39987) in the marimo Python notebook platform is being actively exploited to deploy a UPX-packed Go backdoor named kagent (a new NKAbuse variant) via a typosquatted Hugging Face Space; attackers conducted credential harvesting, stole AWS and API keys, pivoted to PostgreSQL/Redis instances, and used the decentralized NKN blockchain for resilient C2. Defenders are urged to update marimo to 0.23.0+, hunt for ~/.kagent artifacts and kagent service entries, rotate exposed credentials, block the delivery domain, and monitor for NKN relay patterns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
