None
EN
Fake Security App Used Hugging Face to Push Thousands of Android Malware Files
['Rizwana Omer', 'Dreamer Nature', 'Journalist Trade.']
PhoneWorld
Hugging Face, one of the world’s most widely used platforms for hosting artificial intelligence and machine learning resources, has been abused in a large-scale Android malware campaign that distributed thousands of malicious app variants while evading traditional security warnings.
According to researchers at Romanian cybersecurity firm Bitdefender, threat actors used Hugging Face as a backend hosting service for Android malware, embedding thousands of malicious APK variants inside a dataset repository.
The Lure: A Fake Security AppThe attack chain begins with a deceptive Android dropper app called TrustBastion.
Platform Response and User WarningsBitdefender reported the malicious repositories to Hugging Face, which removed the datasets used in the campaign.
Researchers also published indicators of compromise (IOCs) covering the dropper app, malicious packages, and related network infrastructure.