Skip to main content
See every side of every news story
Published loading...Updated

Hugging Face Platform Hijacked to Send Out Android Malware - Here's What We Know so Far

The campaign used server-side polymorphism to create new Android malware variants every 15 minutes, stealing credentials via fake financial app interfaces, Bitdefender said.

  • Bitdefender researchers found an Android malware campaign that abused the Hugging Face platform to host thousands of APK variants targeting Android devices.
  • The attack begins when users install the TrustBastion dropper app , which shows a mandatory update and downloads malicious code via trustbastioncom redirecting to a Hugging Face dataset repository delivered through Hugging Face CDN.
  • Using Accessibility Services, the payload enables screen overlays, impersonates Alipay and WeChat to steal credentials, and exfiltrates data to a command‑and‑control server, Bitdefender reports.
  • After a takedown, the threat actor used server‑side polymorphism to generate rapid payload variants and resurfaced as `Premium Club` soon, with the same malicious code.
  • Bitdefender informed Hugging Face and the platform removed malicious datasets while researchers published indicators of compromise and advised Android users to avoid third-party installs and review permissions.
Insights by Ground AI
Podcasts & Opinions

14 Articles

Global Security Mag OnlineGlobal Security Mag Online
Reposted by
Global Security Mag OnlineGlobal Security Mag Online

Bitdefender publishes a study on an Android campaign that is particularly sensitive and stealthy, always active, in which cybercriminals hijack Hugging Face's infrastructure to spread large-scale malware. Hugging Face is a community and an open source platform of reference in the field of AI, often described as the "GitHub of the machine learning". Once installed, malware allows real-time surveillance and recording of activity on the screen, the…

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 100% of the sources are Center
100% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

BleepingComputer broke the news in on Thursday, January 29, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal