Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Malicious npm Package Exploits Hugging Face for Cyber Attacks

Malicious npm Package Exploits Hugging Face for Cyber Attacks

Posted on April 23, 2026 By CWS

A recently discovered npm package, known as js-logger-pack, has covertly transformed Hugging Face, a well-respected AI model hosting service, into a platform for malware distribution and data exfiltration. This incident highlights a new tactic in cyber attacks, where legitimate cloud services are misused to execute supply chain attacks while masking malicious activities.

Stealthy Attack Methodology

The npm package initially appeared innocuous, as it loaded a seemingly legitimate logger upon installation. However, the real threat was embedded within a postinstall script, which initiated a concealed background process. This allowed the npm installation to complete without raising suspicion, while a hidden downloader continued to operate.

Once executed, the script downloaded one of four malicious binaries depending on the operating system, from a public repository on Hugging Face, controlled by an entity identified as Lordplay/system-releases. Security analysts from JFrog extracted and examined the JavaScript payloads hidden within these binaries, confirming that the same malicious code was consistently used across all platforms.

Persistence and Exfiltration Techniques

After deployment, the malware ensured its persistence using native platform methods such as scheduled tasks on Windows, LaunchAgents on macOS, and systemd user units on Linux. It then began transmitting system information to a pre-configured command-and-control server through a WebSocket connection. This server facilitated remote access for data manipulation and further payload deployment.

Remarkably, the campaign’s exfiltration strategy employed Hugging Face’s infrastructure for storing stolen data. Instead of using private servers, the attacker stored extracted data in private datasets on Hugging Face, minimizing direct server exposure and complicating detection efforts.

Strategic Advantages for Attackers

Utilizing Hugging Face for data storage presented significant operational benefits for the attackers. It reduced the need for direct server data storage, thereby lowering exposure risks. The malware was designed to manage uploads efficiently, ensuring no data was lost even if connectivity issues occurred.

Additionally, the malware had capabilities to disrupt user sessions by killing browser processes and clearing credentials, thereby facilitating keylogging. Any credentials entered post-logout could be quickly captured and sent to the attacker’s datasets.

Preventive Measures and Recommendations

To mitigate the threat, it is crucial to immediately rotate all sensitive credentials, including AWS keys, SSH keys, npm tokens, and database passwords. Removing persistence mechanisms, such as scheduled tasks and registry keys, is also essential. Clearing the npm cache and disabling postinstall scripts by using npm config set ignore-scripts true can prevent further malicious installations.

Systems that have run the js-logger-pack package should be treated as fully compromised until all secrets are rotated, and persistence artifacts are removed. It is vital to carefully review all dependency changes to prevent similar incidents in the future.

Cyber Security News Tags:cloud services, command-and-control server, cross-platform malware, Cybersecurity, data exfiltration, data theft, Hugging Face, JFrog Security, Malware, npm package, Persistence, supply chain attack

Post navigation

Previous Post: North Korean Cyber Scheme Exploits IT Jobs Globally
Next Post: Hackers Exploit Microsoft Teams in Sophisticated Attack

Related Posts

Instagram Confirms no System Breach and Fixed External Party Password Reset Issue Instagram Confirms no System Breach and Fixed External Party Password Reset Issue Cyber Security News
Kimsuky Uses LNK Files to Deploy Python Backdoor Kimsuky Uses LNK Files to Deploy Python Backdoor Cyber Security News
Russian Basketball Player Arrested over Alleged Ransomware Attack Claims Russian Basketball Player Arrested over Alleged Ransomware Attack Claims Cyber Security News
CISA Adds Digiever Authorization Vulnerability to KEV List Following Active Exploitation CISA Adds Digiever Authorization Vulnerability to KEV List Following Active Exploitation Cyber Security News
Kali Linux 2025.4 Released With 3 New Hacking Tools and Wifipumpkin3 Kali Linux 2025.4 Released With 3 New Hacking Tools and Wifipumpkin3 Cyber Security News
NANOREMOTE Malware Leverages  Google Drive API for Command-and-Control (C2) to Attack Windows Systems NANOREMOTE Malware Leverages  Google Drive API for Command-and-Control (C2) to Attack Windows Systems Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • New Tool EDRChoker Disrupts EDR Agents via QoS Throttling
  • Emphere Secures $2.1M to Enhance AI Security Solutions
  • Instagram Addresses Password Reset Vulnerability
  • CISA Alerts on Linux Kernel Vulnerability Threat
  • ChatGPT Lockdown Mode Enhances Security Against Data Threats

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • New Tool EDRChoker Disrupts EDR Agents via QoS Throttling
  • Emphere Secures $2.1M to Enhance AI Security Solutions
  • Instagram Addresses Password Reset Vulnerability
  • CISA Alerts on Linux Kernel Vulnerability Threat
  • ChatGPT Lockdown Mode Enhances Security Against Data Threats

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark