#PythonExploit
CVE-2026-39987 in the marimo Python notebook was exploited within days to deploy an NKAbuse blockchain botnet via a typosquatted HuggingFace Space. Attackers used reverse shells, PostgreSQL/Redis pivots, and credential harvesting. #BotnetAttack #PythonExploit
CVE-2026-39987 update: How attackers weaponized marimo to deploy a blockchain botnet via HuggingFace
Three days after disclosure of a pre-auth remote code execution in the marimo Python notebook platform (GHSA-2679-6mx9-h9xc / CVE-2026-39987), multiple actors exploited the flaw to harvest credentials, run reverse shells, pivot to PostgreSQL/Redis, and deploy a previously undocumented NKAbuse variant hosted on a typosquatted HuggingFace Space. Defenders should look for the VS Code typosquat vsccode-modetx.hf.space, the kagent implant and installer, rotated credentials, and runtime behaviors such as reverse shells and systemd/crontab persistence #NKAbuse #marimo
www.hendryadrian.com
April 16, 2026 at 6:15 AM