Weaponized CVE-2026-39987 Pushes Blockchain Backdoor Through Hugging Face
ID: 60e3bc57-3377-5df8-868b-3354cc30f4a4
STIX ID: report--60e3bc57-3377-5df8-868b-3354cc30f4a4
Feed Name: GBHackers
Threat Score
Active campaigns are exploiting a critical pre-auth RCE (CVE-2026-39987) in the Marimo notebook platform to install an NKAbuse backdoor delivered from a Hugging Face typosquat (vsccode-modetx). Attackers rapidly harvest environment variables and credentials, pivot to PostgreSQL and Redis, and achieve persistence via a UPX-packed Go binary (kagent) that uses the NKN blockchain for C2; the report includes IOCs (payload URLs, dropper script, DNS oracle) and immediate mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
