Hugging Face platform hijacked to send Android malware – here’s what we know so far


  • Hackers used Hugging Face to deliver Android malware via the fake antivirus app TrustBastion
  • Malware steals screenshots, lock codes and payment logins and exfiltrates data to hacker servers
  • The campaign continued with new repositories despite the removal, highlighting the risks of unverified app source

Hackers are misusing the Hugging Face platform to deliver Android malware that can completely take over compromised endpoints, experts have warned.

Hugging Face is an open platform for AI tools and machine learning where users can host and distribute AL, NLP or ML models – but it seems that it is also sometimes used as a launching pad for poisoned models.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top