logo

Malicious npm Package Hijacks Hugging Face for Malware Delivery

ID: 49de91b5-0c4e-509a-a07d-382ca6d9f23d

STIX ID: report--49de91b5-0c4e-509a-a07d-382ca6d9f23d

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-04-23

Date Updated: 2026-04-23

Author: Mayura Kathir

...
...

A malicious npm package named js-logger-pack was found to drop and run a cross-platform implant (MicrosoftSystem64) packaged as Node.js SEAs; the implant registers persistence, logs keystrokes, harvests files and secrets, and supports remote commands. The campaign abuses Hugging Face both to host second‑stage binaries and to receive exfiltrated data into private datasets, and the report includes indicators such as the malicious package, the Hugging Face repo Lordplay/system-releases, and a C2 IP (195.201.194.107:8010). Defenders are advised to treat affected hosts as fully compromised, rotate secrets, remove persistence, purge the package and lockfiles, and reinstall dependencies with script execution disabled.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.