Hugging Face Abused To Spread Blockchain-Based Backdoor In CVE-2026-39987 Attacks
ID: 981e5125-1dec-537c-ba66-99f40f93cf2b
STIX ID: report--981e5125-1dec-537c-ba66-99f40f93cf2b
Feed Name: Cyber Press
**Executive summary:** Between April 11–14, 2026 threat actors rapidly weaponized a critical unauthenticated RCE in the Marimo notebook platform (CVE-2026-39987), registering 662 exploit events from 11 IP addresses across 10 countries; attackers used a typosquatted Hugging Face Space to host a shell dropper that deployed a Go-based NKAbuse backdoor (named "kagent") leveraging NKN blockchain C2, while performing credential harvesting, database and Redis enumeration, DNS-based out-of-band verification, and establishing cross-platform persistence.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
