Malicious npm Package Turns Hugging Face Into Malware CDN and Exfiltration Backend
ID: a446dd2d-1d85-54ca-a8fe-971aeca4ce97
STIX ID: report--a446dd2d-1d85-54ca-a8fe-971aeca4ce97
Feed Name: cybersecurityNews.com
A malicious npm package named js-logger-pack abused npm postinstall hooks to run hidden downloaders that fetch cross-platform Node.js executables containing the same JavaScript implant; the implant establishes persistence, connects to a hard-coded C2 (195.201.194.107) over WebSocket, captures files/credentials/keystrokes/clipboard data, and exfiltrates stolen content by uploading gzip archives into private Hugging Face datasets under attacker control, enabling stealthy, resilient data theft and further payload deployment.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
