Malicious npm Package Hijacks Hugging Face for Malware Delivery
ID: 49de91b5-0c4e-509a-a07d-382ca6d9f23d
STIX ID: report--49de91b5-0c4e-509a-a07d-382ca6d9f23d
Feed Name: GBHackers
A malicious npm package named js-logger-pack was found to drop and run a cross-platform implant (MicrosoftSystem64) packaged as Node.js SEAs; the implant registers persistence, logs keystrokes, harvests files and secrets, and supports remote commands. The campaign abuses Hugging Face both to host second‑stage binaries and to receive exfiltrated data into private datasets, and the report includes indicators such as the malicious package, the Hugging Face repo Lordplay/system-releases, and a C2 IP (195.201.194.107:8010). Defenders are advised to treat affected hosts as fully compromised, rotate secrets, remove persistence, purge the package and lockfiles, and reinstall dependencies with script execution disabled.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
