Home / Companies / Sysdig / Blog / Post Details
Content Deep Dive

CVE-2026-39987 update: How attackers weaponized marimo to deploy a blockchain botnet via HuggingFace

Blog post from Sysdig

Post Details
Company
Date Published
Author
Michael Clark
Word Count
2,414
Company Posts That Month
26
Language
English
Hacker News Points
-
Post removed?
No
Summary

The Sysdig Threat Research Team (TRT) identified an exploit in the marimo Python notebook platform, CVE-2026-39987, which allows attackers to deploy a blockchain botnet through HuggingFace Spaces. This exploit was observed shortly after the vulnerability was disclosed, leading to various attacks, including the deployment of a new NKAbuse malware variant. The attacks involved credential harvesting, reverse shell operations, and lateral movements to databases like PostgreSQL and Redis. The attackers also utilized DNS exfiltration techniques and leveraged HuggingFace Spaces for malware distribution, exploiting the platform's clean reputation. The incidents highlight the increasing targeting of AI/ML infrastructure, emphasizing the importance of behavioral detection, credential rotation, and careful monitoring of AI/ML platform dependencies to defend against sophisticated threats.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Kubernetes 3 2,306 381 103 +25%
AI Agents 1 4,430 1,100 236 -3%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.