logo

NPM Menace Exposes Hugging Face As Backend For Data Theft and Malware Delivery

ID: 41c8361e-9046-5f78-a647-61d336daca01

STIX ID: report--41c8361e-9046-5f78-a647-61d336daca01

Feed Name: Cyber Press

Threat Score
78/100

Date Published: 2026-04-23

Date Updated: 2026-04-23

Author: Varshini

...
...

A malicious npm package (js-logger-pack ≤1.1.27) uses a postinstall script to spawn a detached downloader that retrieves a cross-platform implant from a Hugging Face dataset; the implant provides persistence, keylogging, clipboard monitoring, and archives exfiltration to attacker-controlled Hugging Face storage, impacting Windows, macOS, and Linux systems and representing a supply-chain-style campaign.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.