Hackers Leveraged Hugging Face and ClawHub With 575+ Malicious Skills to Deploy Malware
ID: 7b4ce1f7-801b-582c-a753-c04d931cfb46
STIX ID: report--7b4ce1f7-801b-582c-a753-c04d931cfb46
Feed Name: cybersecurityNews.com
Acronis TRU uncovered a large-scale supply-chain malware campaign that abused Hugging Face and ClawHub/OpenClaw to distribute trojanized skills and model/dataset staging points hosting trojans, cryptominers, and macOS infostealers (e.g., AMOS Stealer); attackers used indirect prompt injection in agent skills, in-memory process injection (explorer.exe), encrypted C2 (velvet-parrot.com), and persistence mechanisms, with 575 malicious OpenClaw skills attributed largely to two developer accounts and identified IoCs such as 91.92.242.30.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
