Trending Hugging Face Repo Turned Into Malware Delivery

A top-ranked model-hub listing can be a malware distribution channel, not a trust signal. In this case, trending placement and a near-clone model card helped the fake project look safe enough to pull Windows users into a credential-theft campaign. HiddenLayer found the typosquatted Open-OSS/privacy-filter repo impersonating OpenAI’s Privacy Filter. It reached #1 trending and about 244,000 downloads before removal, and its loader.py fetched a Windows infostealer that targeted browser data, tokens, wallets, SSH and VPN credentials, and local files. The risk is not just the repo being gone. Anyone who downloaded its artifacts may already have imported malware onto developer workstations or Windows endpoints, and the platform’s own discovery features were part of the delivery path.

Part of the PlainSec briefing for 2026-05-13

Sources