Hackers exploit Marimo flaw to deploy NKAbuse malware from Hugging Face
ID: d648921d-4a56-541c-a744-db8c3f6ddb3f
STIX ID: report--d648921d-4a56-541c-a744-db8c3f6ddb3f
Feed Name: Bleeping Computer
Threat Score
Sysdig observed active exploitation of Marimo RCE (CVE-2026-39987) where attackers used a Hugging Face Space (vsccode-modetx) to host a dropper (install-linux.sh) and a 'kagent' binary — a new NKAbuse variant functioning as a remote access trojan that establishes persistence, executes shell commands, and facilitates credential theft and lateral movement to PostgreSQL and Redis; operators should upgrade to Marimo 0.23.0 or block access to the '/terminal/ws' endpoint.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
