logo

Hugging Face Abused To Spread Blockchain-Based Backdoor In CVE-2026-39987 Attacks

ID: 981e5125-1dec-537c-ba66-99f40f93cf2b

STIX ID: report--981e5125-1dec-537c-ba66-99f40f93cf2b

Feed Name: Cyber Press

Threat Score
80/100

Date Published: 2026-04-17

Date Updated: 2026-04-17

Author: Varshini

...
...

**Executive summary:** Between April 11–14, 2026 threat actors rapidly weaponized a critical unauthenticated RCE in the Marimo notebook platform (CVE-2026-39987), registering 662 exploit events from 11 IP addresses across 10 countries; attackers used a typosquatted Hugging Face Space to host a shell dropper that deployed a Go-based NKAbuse backdoor (named "kagent") leveraging NKN blockchain C2, while performing credential harvesting, database and Redis enumeration, DNS-based out-of-band verification, and establishing cross-platform persistence.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.