A fake OpenAI repository has taken the top spot on Hugging Face, but all it does is push data-stealing malware



  • Attackers compromised an OpenAI repository on HuggingFace and distributed a data stealer disguised as a “privacy filter” model.
  • The malware disabled SSL checks, escalated privileges, and implemented the sefira payload to steal credentials, crypto wallets and system data
  • The fake repository reached 244,000 downloads and briefly topped the HuggingFace rankings before its removal, and other linked malicious repositories were also removed.

Experts warned that cybercriminals were able to counterfeit OpenAI products to distribute information-stealing malware to more than 240,000 computers before being detected and removed.

Security researchers HiddenLayer said they detected a new repository on HuggingFace called Open-OSS/privacy-filter.

Leave a Comment

Your email address will not be published. Required fields are marked *

A fake OpenAI repository has taken the top spot on Hugging Face, but all it does is push data-stealing malware



  • Attackers compromised an OpenAI repository on HuggingFace and distributed a data stealer disguised as a “privacy filter” model.
  • The malware disabled SSL checks, escalated privileges, and implemented the sefira payload to steal credentials, crypto wallets and system data
  • The fake repository reached 244,000 downloads and briefly topped the HuggingFace rankings before its removal, and other linked malicious repositories were also removed.

Experts warned that cybercriminals were able to counterfeit OpenAI products to distribute information-stealing malware to more than 240,000 computers before being detected and removed.

Security researchers HiddenLayer said they detected a new repository on HuggingFace called Open-OSS/privacy-filter.

Leave a Comment

Your email address will not be published. Required fields are marked *