Threat reportMalwareTL-2026-0025

Hugging Face Abused for Android Malware Distribution - Credential Stealer Campaign

highACTIVE

Hugging Face Abused for Android Malware Distribution (TL-2026-0025), also tracked as Hugging Face Malware, is a high-severity malware campaign scored CVSS 7.5, first published 2026-02-02. It has no confirmed attribution, affects Android Android Devices, maps to 18 MITRE ATT&CK techniques (T1005, T1027, T1036), and is covered by 12 detection rules and 22 indicators of compromise.

CVSS
7.5/10High
CVEs
0None referenced
Techniques
18MITRE ATT&CK
Actors
0Not attributed
Detection rules
12SPL · KQL · Sigma
IOCs
22Indicators of compromise

Key facts for TL-2026-0025

Threat ID
TL-2026-0025
Also known as
Hugging Face Malware, Android Banking Trojan, AI Platform Abuse
Severity
HIGH
CVSS
7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N)
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution confidence
NONE
Motivation
FINANCIAL
Target sectors
Artificial Intelligence, Software Development, Research, Finance, All Android Users
Target regions
Global
Detection rules
12
Indicators of compromise
22

How Hugging Face Abused for Android Malware Distribution works

Hugging Face — the dominant AI/ML model-sharing platform with 1M+ repositories — is being abused as a trusted distribution channel for Android credential-stealing malware and as a vector for code execution via malicious ML model files. Attackers exploit Hugging Face's trusted reputation, free Git LFS hosting, and permissive upload policies to host Android APKs containing banking trojans and credential stealers, distribute malicious PyTorch/Keras models with embedded reverse shells via Python pickle deserialization, and leverage the platform's CDN infrastructure to serve malware from a domain that bypasses corporate URL filters and endpoint protections. JFrog Security Research identified ~100 genuinely malicious models on the platform, including PyTorch models with embedded reverse shells (baller423/goober2) connecting to attacker C2 servers. The Android malware distribution vector is particularly insidious: threat actors upload credential-stealing APKs disguised as AI demo applications to Hugging Face Spaces, exploiting the platform's huggingface.co domain trust to evade download blocks and app store security. Hugging Face's security mitigations — ClamAV malware scanning, pickle scanning, and the safetensors format — provide partial protection but cannot fully prevent abuse of the platform as a trusted file hosting service.

Hugging Face is the GitHub of machine learning — the central hub where researchers, developers, and organizations share ML models, datasets, and applications. With over 1 million repositories and hundreds of thousands of active users, it has become critical AI infrastructure. This trusted position makes it an attractive target for supply chain attacks.

**Attack Vector 1: Android Malware Distribution via Hugging Face**

Threat actors abuse Hugging Face as a trusted CDN for distributing Android credential-stealing malware:

1. Attacker creates a Hugging Face repository disguised as an AI demo application or model showcase 2. Repository contains Android APK files (credential stealers, banking trojans) hosted via Git LFS 3. Malware is distributed via links to huggingface.co — a domain trusted by corporate firewalls, URL filters, and email security gateways 4. Victims download APKs believing they are legitimate AI applications from a trusted platform 5. Android malware harvests banking credentials, SMS OTPs, contacts, and device data 6. Data exfiltrated to attacker C2 infrastructure

The key enabler is Hugging Face's domain reputation — huggingface.co is whitelisted by most security tools as a legitimate AI platform, making it an ideal malware hosting service that bypasses traditional defenses.

**Attack Vector 2: Malicious ML Models — Pickle Deserialization RCE**

JFrog Security Research documented a more sophisticated attack: malicious ML models that execute arbitrary code when loaded:

1. **Pickle Deserialization Attack**: PyTorch models use Python's pickle format for serialization. Pickle files can contain arbitrary Python code that executes during deserialization. Attackers embed reverse shells, credential stealers, and backdoors in model files using the __reduce__ method.

2. **Real-World Example — baller423/goober2**: JFrog discovered a PyTorch model containing a full reverse shell payload connecting to IP 210.117.212.93 (KREONet — Korea Research Environment Open NETwork) on port 4242. The payload was cross-platform: pty.spawn('/bin/sh') on Linux, PowerShell subprocess on Windows.

3. **Scale**: JFrog identified approximately 100 genuinely malicious models on Hugging Face (excluding false positives and bug bounty PoCs). PyTorch models had the highest prevalence, followed by TensorFlow Keras models.

4. **Keras Lambda Layer Attack**: TensorFlow Keras models can execute code through Lambda layers. While Hugging Face's Transformers library mitigates this by only loading weights (not full model architecture), direct library loading remains vulnerable.

5. **Evasion Techniques**: Researchers documented techniques to bypass Hugging Face's pickle scanning, including encoding payloads in non-standard ways and using model formats not covered by current scanners.

**Attack Vector 3: Hugging Face Spaces as Phishing/Malware Infrastructure**

Hugging Face Spaces (hosted applications) can be weaponized: - Host convincing phishing pages on *.hf.space subdomains - Serve drive-by download payloads from trusted infrastructure - Create fake AI tool demos that harvest user credentials - Use Hugging Face's Gradio/Streamlit integration to build interactive social engineering pages

**Hugging Face Security Measures (Partial Mitigations)**: - ClamAV malware scanning on all uploaded files - Pickle scanning that flags unsafe models (but doesn't block downloads) - Safetensors format — safe alternative to pickle that prevents code execution - Secrets scanning for leaked credentials in repositories - Community reporting system for malicious content - Third-party scanning partnerships (JFrog, Protect AI)

**Critical Gap**: Hugging Face marks unsafe models with a warning but does NOT block downloads. Users can still download and execute flagged malicious models. This is by design (research flexibility) but creates real risk.

**Impact on AI Supply Chain**: Compromised ML models create cascading supply chain effects: a backdoored model downloaded by one researcher gets incorporated into downstream applications, fine-tuned models, and production systems — amplifying the initial compromise across the entire AI ecosystem.

MITRE ATT&CK techniques used in TL-2026-0025

collection

T1005 Data from Local System; T1056 Input Capture

defense-evasion

T1027 Obfuscated Files or Information; T1036 Masquerading

exfiltration

T1041 Exfiltration Over C2 Channel

execution

T1059 Command and Scripting Interpreter; T1204 User Execution

command-and-control

T1071 Application Layer Protocol; T1105 Ingress Tool Transfer

discovery

T1082 System Information Discovery; T1083 File and Directory Discovery

initial-access

T1195 Supply Chain Compromise; T1199 Trusted Relationship; T1566 Phishing

credential-access

T1528 Steal Application Access Token; T1552 Unsecured Credentials

defense-impairment

T1553 Subvert Trust Controls

persistence

T1554 Compromise Host Software Binary

Affected products and versions in Hugging Face Abused for Android Malware Distribution

  • Android — Android Devices
    Vulnerable versions: All versions

Remediation for Hugging Face Abused for Android Malware Distribution

Immediate actions

  • Block APK downloads from huggingface.co at proxy/firewall
  • Scan managed Android devices for apps with suspicious permission combinations
  • Alert users about sideloading risks
  • Check for recently installed unknown apps

Workarounds

  • Disable 'Install from unknown sources' on Android devices
  • Use Google Play Protect
  • Implement corporate MDM with app allowlisting

Longer-term hardening

  • Enforce sideloading restrictions via MDM
  • Implement mobile threat defense solution
  • User awareness training on APK installation risks
  • Monitor for abuse of other AI/ML platforms for malware distribution

Weaknesses (CWE) in Hugging Face Abused for Android Malware Distribution

CWE-494, CWE-829

Timeline of Hugging Face Abused for Android Malware Distribution

  • HiddenLayer publishes 'Models Are Code' research documenting how ML model serialization formats (pickle, Keras Lambda, ONNX) can execute arbitrary code during deserialization. Establishes that loading an untrusted model is equivalent to running untrusted code. Source: https://hiddenlayer.com/research/models-are-code/
  • HiddenLayer publishes 'Weaponizing ML Models with Ransomware' demonstrating end-to-end attack: malicious PyTorch model containing ransomware payload → uploaded to Hugging Face → downloaded by data scientist → ransomware executed on model load. Source: https://hiddenlayer.com/research/weaponizing-machine-learning-models-with-ransomware/
  • JFrog Security Research publishes discovery of ~100 genuinely malicious models on Hugging Face. Key finding: baller423/goober2 PyTorch model containing cross-platform reverse shell (Linux pty.spawn + Windows PowerShell) connecting to 210.117.212.93:4242 (KREONet South Korea). JFrog deployed honeypot but attacker disconnected after 1 day. Source: https://jfrog.com/blog/data-scientists-targeted-by-malicious-hugging-face-ml-models-with-silent-backdoor/
  • Security researchers identify Hugging Face being used as a CDN for Android credential-stealing malware. APK files disguised as AI demo applications uploaded to repositories, distributed via trusted huggingface.co domain that bypasses corporate URL filters and email security gateways.
  • Hugging Face accelerates safetensors adoption as the default model format — eliminates code execution risk entirely. However, legacy pickle-based models remain prevalent and downloadable. Third-party scanning partnerships with JFrog and Protect AI expand coverage. Source: https://github.com/huggingface/safetensors
  • Hugging Face surpasses 1 million repositories. As the platform grows, the attack surface expands proportionally — more repositories means more opportunities for malicious content to hide among legitimate models. Malware scanning (ClamAV) and pickle scanning provide detection but not prevention (flagged models can still be downloaded).
  • As of 2026-05-29, this Hugging Face abuse threat is ACTIVE and escalating: both vectors are live, with the Open-OSS/privacy-filter fake-OpenAI malicious model hitting #1 trending at 244K downloads (HiddenLayer/THN, May 7 2026) and Bitdefender's TrustBastion/Premium Club Android RAT campaign (Jan-Feb 2026). Takedowns occur but operators immediately resurface, so the record's "CONTAINED" status is no longer accurate.

Sources cited for Hugging Face Abused for Android Malware Distribution

Detection coverage for TL-2026-0025

As of 2026-02-02, Threadlinqs Intelligence publishes 12 detection rule(s) for TL-2026-0025 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

12 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
22 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats