Threat reportMalwareTL-2026-0025
Hugging Face Abused for Android Malware Distribution - Credential Stealer Campaign
Hugging Face Abused for Android Malware Distribution (TL-2026-0025), also tracked as Hugging Face Malware, is a high-severity malware campaign scored CVSS 7.5, first published 2026-02-02. It has no confirmed attribution, affects Android Android Devices, maps to 18 MITRE ATT&CK techniques (T1005, T1027, T1036), and is covered by 12 detection rules and 22 indicators of compromise.
- CVSS
- 7.5/10High
- CVEs
- 0None referenced
- Techniques
- 18MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 12SPL · KQL · Sigma
- IOCs
- 22Indicators of compromise
Key facts for TL-2026-0025
- Threat ID
- TL-2026-0025
- Also known as
- Hugging Face Malware, Android Banking Trojan, AI Platform Abuse
- Severity
- HIGH
- CVSS
- 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N)
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- FINANCIAL
- Target sectors
- Artificial Intelligence, Software Development, Research, Finance, All Android Users
- Target regions
- Global
- Detection rules
- 12
- Indicators of compromise
- 22
How Hugging Face Abused for Android Malware Distribution works
Hugging Face — the dominant AI/ML model-sharing platform with 1M+ repositories — is being abused as a trusted distribution channel for Android credential-stealing malware and as a vector for code execution via malicious ML model files. Attackers exploit Hugging Face's trusted reputation, free Git LFS hosting, and permissive upload policies to host Android APKs containing banking trojans and credential stealers, distribute malicious PyTorch/Keras models with embedded reverse shells via Python pickle deserialization, and leverage the platform's CDN infrastructure to serve malware from a domain that bypasses corporate URL filters and endpoint protections. JFrog Security Research identified ~100 genuinely malicious models on the platform, including PyTorch models with embedded reverse shells (baller423/goober2) connecting to attacker C2 servers. The Android malware distribution vector is particularly insidious: threat actors upload credential-stealing APKs disguised as AI demo applications to Hugging Face Spaces, exploiting the platform's huggingface.co domain trust to evade download blocks and app store security. Hugging Face's security mitigations — ClamAV malware scanning, pickle scanning, and the safetensors format — provide partial protection but cannot fully prevent abuse of the platform as a trusted file hosting service.
Hugging Face is the GitHub of machine learning — the central hub where researchers, developers, and organizations share ML models, datasets, and applications. With over 1 million repositories and hundreds of thousands of active users, it has become critical AI infrastructure. This trusted position makes it an attractive target for supply chain attacks.
**Attack Vector 1: Android Malware Distribution via Hugging Face**
Threat actors abuse Hugging Face as a trusted CDN for distributing Android credential-stealing malware:
1. Attacker creates a Hugging Face repository disguised as an AI demo application or model showcase 2. Repository contains Android APK files (credential stealers, banking trojans) hosted via Git LFS 3. Malware is distributed via links to huggingface.co — a domain trusted by corporate firewalls, URL filters, and email security gateways 4. Victims download APKs believing they are legitimate AI applications from a trusted platform 5. Android malware harvests banking credentials, SMS OTPs, contacts, and device data 6. Data exfiltrated to attacker C2 infrastructure
The key enabler is Hugging Face's domain reputation — huggingface.co is whitelisted by most security tools as a legitimate AI platform, making it an ideal malware hosting service that bypasses traditional defenses.
**Attack Vector 2: Malicious ML Models — Pickle Deserialization RCE**
JFrog Security Research documented a more sophisticated attack: malicious ML models that execute arbitrary code when loaded:
1. **Pickle Deserialization Attack**: PyTorch models use Python's pickle format for serialization. Pickle files can contain arbitrary Python code that executes during deserialization. Attackers embed reverse shells, credential stealers, and backdoors in model files using the __reduce__ method.
2. **Real-World Example — baller423/goober2**: JFrog discovered a PyTorch model containing a full reverse shell payload connecting to IP 210.117.212.93 (KREONet — Korea Research Environment Open NETwork) on port 4242. The payload was cross-platform: pty.spawn('/bin/sh') on Linux, PowerShell subprocess on Windows.
3. **Scale**: JFrog identified approximately 100 genuinely malicious models on Hugging Face (excluding false positives and bug bounty PoCs). PyTorch models had the highest prevalence, followed by TensorFlow Keras models.
4. **Keras Lambda Layer Attack**: TensorFlow Keras models can execute code through Lambda layers. While Hugging Face's Transformers library mitigates this by only loading weights (not full model architecture), direct library loading remains vulnerable.
5. **Evasion Techniques**: Researchers documented techniques to bypass Hugging Face's pickle scanning, including encoding payloads in non-standard ways and using model formats not covered by current scanners.
**Attack Vector 3: Hugging Face Spaces as Phishing/Malware Infrastructure**
Hugging Face Spaces (hosted applications) can be weaponized: - Host convincing phishing pages on *.hf.space subdomains - Serve drive-by download payloads from trusted infrastructure - Create fake AI tool demos that harvest user credentials - Use Hugging Face's Gradio/Streamlit integration to build interactive social engineering pages
**Hugging Face Security Measures (Partial Mitigations)**: - ClamAV malware scanning on all uploaded files - Pickle scanning that flags unsafe models (but doesn't block downloads) - Safetensors format — safe alternative to pickle that prevents code execution - Secrets scanning for leaked credentials in repositories - Community reporting system for malicious content - Third-party scanning partnerships (JFrog, Protect AI)
**Critical Gap**: Hugging Face marks unsafe models with a warning but does NOT block downloads. Users can still download and execute flagged malicious models. This is by design (research flexibility) but creates real risk.
**Impact on AI Supply Chain**: Compromised ML models create cascading supply chain effects: a backdoored model downloaded by one researcher gets incorporated into downstream applications, fine-tuned models, and production systems — amplifying the initial compromise across the entire AI ecosystem.
MITRE ATT&CK techniques used in TL-2026-0025
collection
T1005 Data from Local System; T1056 Input Capture
defense-evasion
T1027 Obfuscated Files or Information; T1036 Masquerading
exfiltration
T1041 Exfiltration Over C2 Channel
execution
T1059 Command and Scripting Interpreter; T1204 User Execution
command-and-control
T1071 Application Layer Protocol; T1105 Ingress Tool Transfer
discovery
T1082 System Information Discovery; T1083 File and Directory Discovery
initial-access
T1195 Supply Chain Compromise; T1199 Trusted Relationship; T1566 Phishing
credential-access
T1528 Steal Application Access Token; T1552 Unsecured Credentials
defense-impairment
persistence
Affected products and versions in Hugging Face Abused for Android Malware Distribution
- Android — Android Devices
Vulnerable versions: All versions
Remediation for Hugging Face Abused for Android Malware Distribution
Immediate actions
- Block APK downloads from huggingface.co at proxy/firewall
- Scan managed Android devices for apps with suspicious permission combinations
- Alert users about sideloading risks
- Check for recently installed unknown apps
Workarounds
- Disable 'Install from unknown sources' on Android devices
- Use Google Play Protect
- Implement corporate MDM with app allowlisting
Longer-term hardening
- Enforce sideloading restrictions via MDM
- Implement mobile threat defense solution
- User awareness training on APK installation risks
- Monitor for abuse of other AI/ML platforms for malware distribution
Weaknesses (CWE) in Hugging Face Abused for Android Malware Distribution
Timeline of Hugging Face Abused for Android Malware Distribution
- HiddenLayer publishes 'Models Are Code' research documenting how ML model serialization formats (pickle, Keras Lambda, ONNX) can execute arbitrary code during deserialization. Establishes that loading an untrusted model is equivalent to running untrusted code. Source: https://hiddenlayer.com/research/models-are-code/
- HiddenLayer publishes 'Weaponizing ML Models with Ransomware' demonstrating end-to-end attack: malicious PyTorch model containing ransomware payload → uploaded to Hugging Face → downloaded by data scientist → ransomware executed on model load. Source: https://hiddenlayer.com/research/weaponizing-machine-learning-models-with-ransomware/
- JFrog Security Research publishes discovery of ~100 genuinely malicious models on Hugging Face. Key finding: baller423/goober2 PyTorch model containing cross-platform reverse shell (Linux pty.spawn + Windows PowerShell) connecting to 210.117.212.93:4242 (KREONet South Korea). JFrog deployed honeypot but attacker disconnected after 1 day. Source: https://jfrog.com/blog/data-scientists-targeted-by-malicious-hugging-face-ml-models-with-silent-backdoor/
- Security researchers identify Hugging Face being used as a CDN for Android credential-stealing malware. APK files disguised as AI demo applications uploaded to repositories, distributed via trusted huggingface.co domain that bypasses corporate URL filters and email security gateways.
- Hugging Face accelerates safetensors adoption as the default model format — eliminates code execution risk entirely. However, legacy pickle-based models remain prevalent and downloadable. Third-party scanning partnerships with JFrog and Protect AI expand coverage. Source: https://github.com/huggingface/safetensors
- Hugging Face surpasses 1 million repositories. As the platform grows, the attack surface expands proportionally — more repositories means more opportunities for malicious content to hide among legitimate models. Malware scanning (ClamAV) and pickle scanning provide detection but not prevention (flagged models can still be downloaded).
- As of 2026-05-29, this Hugging Face abuse threat is ACTIVE and escalating: both vectors are live, with the Open-OSS/privacy-filter fake-OpenAI malicious model hitting #1 trending at 244K downloads (HiddenLayer/THN, May 7 2026) and Bitdefender's TrustBastion/Premium Club Android RAT campaign (Jan-Feb 2026). Takedowns occur but operators immediately resurface, so the record's "CONTAINED" status is no longer accurate.
Sources cited for Hugging Face Abused for Android Malware Distribution
- JFrog — Data Scientists Targeted by Malicious Hugging Face ML Models with Silent Backdoor
- Hugging Face — Security Documentation
- Hugging Face — Malware Scanning (ClamAV)
- HiddenLayer — Models Are Code
- HiddenLayer — Weaponizing ML Models with Ransomware
- Trail of Bits — Fickling Pickle Analyzer
- Hugging Face — Safetensors Safe Serialization Format
- Hugging Face — Pickle Scanning Documentation
Detection coverage for TL-2026-0025
As of 2026-02-02, Threadlinqs Intelligence publishes 12 detection rule(s) for TL-2026-0025 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.