Marimo Zero-Day Turns AI Demo Hosting Into Malware Delivery
A notebook RCE is not just a code-execution bug here. It gives attackers a fast path to turn a trusted demo environment into a credential-theft and malware-delivery point, and patching the notebook does not undo anything already pulled from the host.
Sysdig says exploitation of CVE-2026-39987 began less than 10 hours after technical details were public. The campaign used Hugging Face Spaces to host a typosquatted Space that delivered a dropper and a new NKAbuse variant, with the activity starting on April 12 and targeting Marimo users through the /terminal/ws attack surface.
The risk now is speed and trust. AI hosting platforms can be repurposed as clean-looking distribution points almost immediately, which shortens the time between disclosure and weaponized delivery for anyone running exposed Marimo instances.