logo

Weaponized CVE-2026-39987 Pushes Blockchain Backdoor Through Hugging Face

ID: 60e3bc57-3377-5df8-868b-3354cc30f4a4

STIX ID: report--60e3bc57-3377-5df8-868b-3354cc30f4a4

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-04-17

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Active campaigns are exploiting a critical pre-auth RCE (CVE-2026-39987) in the Marimo notebook platform to install an NKAbuse backdoor delivered from a Hugging Face typosquat (vsccode-modetx). Attackers rapidly harvest environment variables and credentials, pivot to PostgreSQL and Redis, and achieve persistence via a UPX-packed Go binary (kagent) that uses the NKN blockchain for C2; the report includes IOCs (payload URLs, dropper script, DNS oracle) and immediate mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.