# Hugging Face Abused for Android Malware Distribution - Credential Stealer Campaign

> Hugging Face — the dominant AI/ML model-sharing platform with 1M+ repositories — is being abused as a trusted distribution channel for Android credential-stealing malware and as a vector for code execution via malicious ML model files. Attackers exploit Hugging Face's trusted reputation, free Git LFS hosting, and permissive upload policies to host Android APKs containing banking trojans and credential stealers, distribute malicious PyTorch/Keras models with embedded reverse shells via Python pickle deserialization, and leverage the platform's CDN infrastructure to serve malware from a domain that bypasses corporate URL filters and endpoint protections. JFrog Security Research identified ~100 genuinely malicious models on the platform, including PyTorch models with embedded reverse shells (baller423/goober2) connecting to attacker C2 servers. The Android malware distribution vector is particularly insidious: threat actors upload credential-stealing APKs disguised as AI demo applications to Hugging Face Spaces, exploiting the platform's huggingface.co domain trust to evade download blocks and app store security. Hugging Face's security mitigations — ClamAV malware scanning, pickle scanning, and the safetensors format — provide partial protection but cannot fully prevent abuse of the platform as a trusted file hosting service.

- **Published:** 2026-02-02T21:55:00Z
- **Last reviewed:** 2026-02-02T21:55:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0025
- **ID:** TL-2026-0025
- **Severity:** HIGH (CVSS 7.5)
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 12 · **IOCs:** 22 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Hugging Face is the GitHub of machine learning — the central hub where researchers, developers, and organizations share ML models, datasets, and applications. With over 1 million repositories and hundreds of thousands of active users, it has become critical AI infrastructure. This trusted position makes it an attractive target for supply chain attacks.

**Attack Vector 1: Android Malware Distribution via Hugging Face**

Threat actors abuse Hugging Face as a trusted CDN for distributing Android credential-stealing malware:

1. Attacker creates a Hugging Face repository disguised as an AI demo application or model showcase
2. Repository contains Android APK files (credential stealers, banking trojans) hosted via Git LFS
3. Malware is distributed via links to huggingface.co — a domain trusted by corporate firewalls, URL filters, and email security gateways
4. Victims download APKs believing they are legitimate AI applications from a trusted platform
5. Android malware harvests banking credentials, SMS OTPs, contacts, and device data
6. Data exfiltrated to attacker C2 infrastructure

The key enabler is Hugging Face's domain reputation — huggingface.co is whitelisted by most security tools as a legitimate AI platform, making it an ideal malware hosting service that bypasses traditional defenses.

**Attack Vector 2: Malicious ML Models — Pickle Deserialization RCE**

JFrog Security Research documented a more sophisticated attack: malicious ML models that execute arbitrary code when loaded:

1. **Pickle Deserialization Attack**: PyTorch models use Python's pickle format for serialization. Pickle files can contain arbitrary Python code that executes during deserialization. Attackers embed reverse shells, credential stealers, and backdoors in model files using the __reduce__ method.

2. **Real-World Example — baller423/goober2**: JFrog discovered a PyTorch model containing a full reverse shell payload connecting to IP 210.117.212.93 (KREONet — Korea Research Environment Open NETwork) on port 4242. The payload was cross-platform: pty.spawn('/bin/sh') on Linux, PowerShell subprocess on Windows.

3. **Scale**: JFrog identified approximately 100 genuinely malicious models on Hugging Face (excluding false positives and bug bounty PoCs). PyTorch models had the highest prevalence, followed by TensorFlow Keras models.

4. **Keras Lambda Layer Attack**: TensorFlow Keras models can execute code through Lambda layers. While Hugging Face's Transformers library mitigates this by only loading weights (not full model architecture), direct library loading remains vulnerable.

5. **Evasion Techniques**: Researchers documented techniques to bypass Hugging Face's pickle scanning, including encoding payloads in non-standard ways and using model formats not covered by current scanners.

**Attack Vector 3: Hugging Face Spaces as Phishing/Malware Infrastructure**

Hugging Face Spaces (hosted applications) can be weaponized:
- Host convincing phishing pages on *.hf.space subdomains
- Serve drive-by download payloads from trusted infrastructure  
- Create fake AI tool demos that harvest user credentials
- Use Hugging Face's Gradio/Streamlit integration to build interactive social engineering pages

**Hugging Face Security Measures (Partial Mitigations)**:
- ClamAV malware scanning on all uploaded files
- Pickle scanning that flags unsafe models (but doesn't block downloads)
- Safetensors format — safe alternative to pickle that prevents code execution
- Secrets scanning for leaked credentials in repositories
- Community reporting system for malicious content
- Third-party scanning partnerships (JFrog, Protect AI)

**Critical Gap**: Hugging Face marks unsafe models with a warning but does NOT block downloads. Users can still download and execute flagged malicious models. This is by design (research flexibility) but creates real risk.

**Impact on AI Supply Chain**:
Compromised ML models create cascading supply chain effects: a backdoored model downloaded by one researcher gets incorporated into downstream applications, fine-tuned models, and production systems — amplifying the initial compromise across the entire AI ecosystem.

## MITRE ATT&CK

- T1195 Supply Chain Compromise
- T1199 Trusted Relationship
- T1566 Phishing
- T1059 Command and Scripting Interpreter
- T1204 User Execution
- T1554 Compromise Host Software Binary
- T1036 Masquerading
- T1027 Obfuscated Files or Information
- T1553 Subvert Trust Controls
- T1056 Input Capture
- T1552 Unsecured Credentials
- T1528 Steal Application Access Token
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1005 Data from Local System
- T1071 Application Layer Protocol
- T1105 Ingress Tool Transfer
- T1041 Exfiltration Over C2 Channel

## Sources

- [JFrog — Data Scientists Targeted by Malicious Hugging Face ML Models with Silent Backdoor](https://jfrog.com/blog/data-scientists-targeted-by-malicious-hugging-face-ml-models-with-silent-backdoor/)
- [Hugging Face — Security Documentation](https://huggingface.co/docs/hub/en/security)
- [Hugging Face — Malware Scanning (ClamAV)](https://huggingface.co/docs/hub/en/security-malware)
- [HiddenLayer — Models Are Code](https://hiddenlayer.com/research/models-are-code/)
- [HiddenLayer — Weaponizing ML Models with Ransomware](https://hiddenlayer.com/research/weaponizing-machine-learning-models-with-ransomware/)
- [Trail of Bits — Fickling Pickle Analyzer](https://github.com/trailofbits/fickling)
- [Hugging Face — Safetensors Safe Serialization Format](https://github.com/huggingface/safetensors)
- [Hugging Face — Pickle Scanning Documentation](https://huggingface.co/docs/hub/en/security-pickle)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0025
