TrustBastion Android malware campaign abusing Hugging Face for credential theft
Campaign
Summary
Hide ▲
Show ▼
A new Android malware campaign is abusing Hugging Face as distribution infrastructure to deliver polymorphic APKs that steal credentials from users of financial and payment services.
Related Happenings
Open-OSS/privacy-filter Hugging Face infostealer activity
Malware Activity
H score69
First: 11.05.2026 10:05
Last: 11.05.2026 10:05
Sources 1
About this happening:
A malicious Hugging Face repository called Open-OSS/privacy-filter impersonated OpenAI's Privacy Filter and delivered a Rust-based information stealer to Windows...
Open-OSS/privacy-filter Hugging Face infostealer activity
Malware ActivityAbout this happening: A malicious Hugging Face repository called Open-OSS/privacy-filter impersonated OpenAI's Privacy Filter and delivered a Rust-based information stealer to Windows...
Sefirah infostealer delivered through a malicious Hugging Face repository
Malware Activity
H score16
First: 09.05.2026 17:26
Last: 09.05.2026 17:26
Sources 1
About this happening:
A malicious Hugging Face repository impersonated OpenAI’s Privacy Filter and delivered sefirah, a Rust-based infostealer, to Windows users, creating credential...
Sefirah infostealer delivered through a malicious Hugging Face repository
Malware ActivityAbout this happening: A malicious Hugging Face repository impersonated OpenAI’s Privacy Filter and delivered sefirah, a Rust-based infostealer, to Windows users, creating credential...
Hugging Face Spaces vsccode-modetx dropper campaign
Campaign
H score44
First: 16.04.2026 19:58
Last: 16.04.2026 19:58
Sources 1
About this happening:
The April 12, 2026 campaign abusing Hugging Face Spaces broadened malicious delivery against AI platform users and increased the risk of stealthy payload execution. An att...
Hugging Face Spaces vsccode-modetx dropper campaign
CampaignAbout this happening: The April 12, 2026 campaign abusing Hugging Face Spaces broadened malicious delivery against AI platform users and increased the risk of stealthy payload execution. An att...
EngageLab SDK intent redirection security flaw
Vulnerability
H score29
First: 09.04.2026 20:26
Last: 09.04.2026 20:26
Sources 1
About this happening:
A now-patched intent redirection vulnerability in the EngageLab SDK could let malicious apps bypass the Android security sandbox and access private data in apps us...
EngageLab SDK intent redirection security flaw
VulnerabilityAbout this happening: A now-patched intent redirection vulnerability in the EngageLab SDK could let malicious apps bypass the Android security sandbox and access private data in apps us...
PromptSpy Android malware with Gemini-assisted persistence and spyware capabilities
Malware Activity
H score16
First: 20.02.2026 00:36
Last: 20.02.2026 00:36
Sources 1
About this happening:
The PromptSpy Android malware family now stands out as the first known Android malware to use Google Gemini at runtime, letting it adapt app-pinning steps across devic...
PromptSpy Android malware with Gemini-assisted persistence and spyware capabilities
Malware ActivityAbout this happening: The PromptSpy Android malware family now stands out as the first known Android malware to use Google Gemini at runtime, letting it adapt app-pinning steps across devic...
Timeline
-
30.01.2026 00:08 2 articles · 5mo ago
Bitdefender discloses Hugging Face Android malware campaign
Initial DisclosureBitdefender disclosed an Android malware campaign that abused Hugging Face as a repository for thousands of APK variants and used the TrustBastion dropper with trustbastion[.]com redirects to deliver a malicious payload. The campaign lured victims with scareware-style ads, a fake Google Play update prompt, and a decoy security-tool interface, then used server-side polymorphism to change payloads every 15 minutes, steal credentials from financial services such as Alipay and WeChat, capture screenshots, and abuse Android’s Accessibility Services; the payload-serving repository was later removed and the operation resurfaced as Premium Club.
Show sources
- Hugging Face abused to spread thousands of Android malware variants — www.bleepingcomputer.com — 30.01.2026 00:08
- Android RAT Uses Hugging Face to Host Malware — www.infosecurity-magazine.com — 02.02.2026 12:30