Menu

Post image 1
Post image 2
Post image 3
1 / 3
0

Hugging Face Pulled Dozens of Backdoored Models. Here's the Pattern.

DEV Community·Gabriel Anhaia·about 1 month ago
#A6lsIlxP
#ai#security#pickle#load#model#safetensors
Reading 0:00
15s threshold

Book: AI Agents Pocket Guide Also by me: Prompt Engineering Pocket Guide My project: Hermes IDE | GitHub — an IDE for developers who ship with Claude Code and other AI coding tools Me: xgabriel.com | GitHub In April 2026, a typosquatted Hugging Face Space called vsccode-modetx started serving a Go-based backdoor that used the NKN blockchain for command-and-control , disguising the binary as a Kubernetes agent named kagent . The underlying flaw, tracked as CVE-2026-39987 , gave unauthenticated attackers a full interactive shell on the host that loaded the model. According to Cyberpress's reporting , first active exploitation was logged less than 10 hours after the advisory was published, and over a three-day window attackers from roughly a dozen IP addresses across multiple countries fired hundreds of exploit events. One operator used the foothold to extract AWS access keys, Postgres connection strings, and OpenAI API tokens from environment variables on data-science workstations.…

Continue reading — create a free account

Join HashtagPLUS to read full articles, follow hashtags, vote, and join the conversation.

Read More