logo

Malicious npm Package Turns Hugging Face Into Malware CDN and Exfiltration Backend

ID: a446dd2d-1d85-54ca-a8fe-971aeca4ce97

STIX ID: report--a446dd2d-1d85-54ca-a8fe-971aeca4ce97

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-04-23

Date Updated: 2026-04-23

Author: Tushar Subhra Dutta

...
...

A malicious npm package named js-logger-pack abused npm postinstall hooks to run hidden downloaders that fetch cross-platform Node.js executables containing the same JavaScript implant; the implant establishes persistence, connects to a hard-coded C2 (195.201.194.107) over WebSocket, captures files/credentials/keystrokes/clipboard data, and exfiltrates stolen content by uploading gzip archives into private Hugging Face datasets under attacker control, enabling stealthy, resilient data theft and further payload deployment.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.