Supply Chain Attack Exploits Hugging Face for Malware Distribution and Data Exfiltration

MicrosoftSystem64 is a cross-platform malware built as a Node.js Single Executable Application. It steals credentials, crypto wallets, SSH keys and Telegram sessions, exfiltrating data to attacker-controlled HuggingFace datasets. Originating from a malicious npm package in April 2026, it utilizes embedded runtimes to evade detection.

Pulse ID: 6a1c2fc0a63cda655beac722
Pulse Link: https://otx.alienvault.com/pulse/6a1c2fc0a63cda655beac722
Pulse Author: cryptocti
Created: 2026-05-31 12:55:28

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#CyberSecurity #HuggingFace #InfoSec #Malware #Microsoft #NPM #Nodejs #OTX #OpenThreatExchange #RAT #SSH #SupplyChain #Telegram #Troll #bot #cryptocti

LevelBlue - Open Threat Exchange

Learn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.

LevelBlue Open Threat Exchange
0xSero/Qwen3.6-28B-REAP · Hugging Face

We’re on a journey to advance and democratize artificial intelligence through open source and open science.

openbmb/MiniCPM5-1B · Hugging Face

We’re on a journey to advance and democratize artificial intelligence through open source and open science.

RT @mr_r0b0t: Offizielles @NVIDIAAI GLM5.1-NVFP4 auf @huggingface gesichtet 🤩

mehr auf Arint.info

#AI #GLM5 #HuggingFace #MachineLearning #NVFP4 #NVIDIAAI #arint_info

https://x.com/mr_r0b0t/status/2059973066436853769#m

Arint - SEO+KI (@[email protected])

<p>RT @mr_r0b0t: Offizielles @NVIDIAAI GLM5.1-NVFP4 auf @huggingface gesichtet 🤩</p> <p><a href="https://arint.info/@Arint/116655877930164686">mehr</a> auf <a href="https://arint.info/">Arint.info</a></p> <p>#AI #GLM5 #HuggingFace #MachineLearning #NVFP4 #NVIDIAAI #arint_info</p> <p><a href="https://x.com/mr_r0b0t/status/2059973066436853769#m">https://x.com/mr_r0b0t/status/2059973066436853769#m</a></p>

Mastodon Glitch Edition

RT @jedisct1: Ich habe gerade MiMo V2.5-Coder veröffentlicht. Wenn du 128 GB RAM hast, ist dies eines der besten Modelle, die du lokal betreiben kannst. Es ist schnell und hat in allen meinen Experimenten Qwen 3.6 und DeepSeek 4-Flash übertroffen. https://huggingface.co/jedisct1/MiMo-V2.5-coder-Q2

mehr auf Arint.info

#DeepLearning #HuggingFace #LocalLLM #MachineLearning #OpenSourceAI #arint_info

https://x.com/jedisct1/status/2058827764237525231#m

jedisct1/MiMo-V2.5-coder-Q2 · Hugging Face

We’re on a journey to advance and democratize artificial intelligence through open source and open science.

🤖 [Hugging Face] Warunki dotyczące uprzęży, rusztowania i agenta AI, które warto poznać

🔗 Więcej: https://huggingface.co/blog/agent-glossary

#AI #SztucznaInteligencja #TechNews #HuggingFace #ArtificialIntelligence #technology #socialmedia #si

Harness, Scaffold, and the AI Agent Terms Worth Getting Right

We’re on a journey to advance and democratize artificial intelligence through open source and open science.

Arint - SEO+KI (@[email protected])

<p>RT @coffeecup2020: TurboQuant - Qwopus3.6-27B-v2-TQ34S.gguf</p> <p><a href="https://arint.info/@Arint/116628972364557878">mehr</a> auf <a href="https://arint.info/">Arint.info</a></p> <p>#AI #HuggingFace #MachineLearning #OpenSource #Qwopus #TurboQuant #arint_info</p> <p><a href="https://x.com/coffeecup2020/status/2058117304185999409#m">https://x.com/coffeecup2020/status/2058117304185999409#m</a></p>

Mastodon Glitch Edition

RT @KyleHessling1: BREAKING! Qwopus 3.6 27B is LIVE! Thank you for your patience on this one, but I believe you'll find the wait was worth it! We've benchmarked this thing up and down, verified that it holds at least a 75.25% (152/202) in the initial 202 SWE bench solves. Not a full run of 500, but it shows the agentic coding quality from the original 27B is retained while adding all of the additional Qwopus benefits across many domains. As always, Jackrong is absolutely cooking here! COT quality has improved significantly through the inversion techniques from our Negentropy proof of concept. It also went through thorough curriculum training. You can check out the MMLU pro benchmarks on the model card, but it improved a whopping 10 points over the base model in physics, as well as meaningful jumps in Chemistry, business, and computer science. However, the best part is that I was able to build an entire survival shooter game using this local model entirely. I genuinely was blown away by the results, which you can play right now on my HF space (link in comments below). "Qwopus Commander" was completed in 9 turns of Qwopus 3.6! To test the new long context training, I made it re-output the entire 3000+ line program each turn, and it would make fixes and add features that I requested in large prompts, while perfectly replicating the entire rest of the game from context. What's more is that I did it all at Q8 KV cache quantization, and never had an issue over the entire 303k token run! IMPORTANT: Run it at --temp 0.75 to 1. Mess with it in that range for your use case. Higher temp actually…

mehr auf Arint.info

#GGUF #huggingface #make #rest #science #SWE #Swe #arint_info

https://x.com/KyleHessling1/status/2057853098585108979#m

Arint - SEO+KI (@[email protected])

<p>RT @KyleHessling1: BREAKING! Qwopus 3.6 27B is LIVE! Thank you for your patience on this one, but I believe you'll find the wait was worth it! We've benchmarked this thing up and down, verified that it holds at least a 75.25% (152/202) in the initial 202 SWE bench solves. Not a full run of 500, but it shows the agentic coding quality from the original 27B is retained while adding all of the additional Qwopus benefits across many domains. As always, Jackrong is absolutely cooking here! COT quality has improved significantly through the inversion techniques from our Negentropy proof of concept. It also went through thorough curriculum training. You can check out the MMLU pro benchmarks on the model card, but it improved a whopping 10 points over the base model in physics, as well as meaningful jumps in Chemistry, business, and computer science. However, the best part is that I was able to build an entire survival shooter game using this local model entirely. I genuinely was blown away by the results, which you can play right now on my HF space (link in comments below). "Qwopus Commander" was completed in 9 turns of Qwopus 3.6! To test the new long context training, I made it re-output the entire 3000+ line program each turn, and it would make fixes and add features that I requested in large prompts, while perfectly replicating the entire rest of the game from context. What's more is that I did it all at Q8 KV cache quantization, and never had an issue over the entire 303k token run! IMPORTANT: Run it at --temp 0.75 to 1. Mess with it in that range for your use case. Higher temp actually…</p> <p><a href="https://arint.info/@Arint/116621893018625926">mehr</a> auf <a href="https://arint.info/">Arint.info</a></p> <p>#GGUF #huggingface #make #rest #science #SWE #Swe #arint_info</p> <p><a href="https://x.com/KyleHessling1/status/2057853098585108979#m">https://x.com/KyleHessling1/status/2057853098585108979#m</a></p>

Mastodon Glitch Edition

🤖 [Hugging Face] W kierunku generowania tekstu z prędkością światła za pomocą modeli języka dyfuzyjnego Nemotron-Labs

🔗 Więcej: https://huggingface.co/blog/nvidia/nemotron-labs-diffusion

#AI #SztucznaInteligencja #TechNews #HuggingFace #ArtificialIntelligence #technology #socialmedia #si

Towards Speed-of-Light Text Generation with Nemotron-Labs Diffusion Language Models

A Blog post by NVIDIA on Hugging Face

🤖 [Hugging Face] Skala specjalizacji pokonuje: zmienna strategiczna, którą większość decyzji dotyczących zamówień AI przeocza

🔗 Więcej: https://huggingface.co/blog/Dharma-AI/specialization-beats-scale

#AI #SztucznaInteligencja #TechNews #HuggingFace #ArtificialIntelligence #technology #socialmedia #si

Specialization Beats Scale: A Strategic Variable Most AI Procurement Decisions Overlook

A Blog post by Dharma-AI on Hugging Face