Malware · 125 days ago
A top-ranked model-hub listing can be a malware distribution channel, not a trust signal. In this case, trending placement and a near-clone model card helped the fake project look safe enough to pull Windows users into a credential-theft campaign.
HiddenLayer found the typosquatted Open-OSS/privacy-filter repo impersonating OpenAI’s Privacy Filter. It reached #1 trending and about 244,000 downloads before removal, and its loader.py fetched a Windows infostealer that targeted browser data, tokens, wallets, SSH and VPN credentials, and local files.
The risk is not just the repo being gone. Anyone who downloaded its artifacts may already have imported malware onto developer workstations or Windows endpoints, and the platform’s own discovery features were part of the delivery path.
4 sources covering this story
Hugging Face Packages Weaponized With a Single File Tweak
A tokenizer library file present in Hugging Face AI models can be manipulated to hijack the model's outputs and exfiltrate data.
Malicious Hugging Face Repository Typosquats OpenAI
HiddenLayer reveals infostealer malware in a Hugging Face repository
Fake OpenAI Privacy Filter Repo Hits #1 on Hugging Face, Draws 244K Downloads
Fake OpenAI Privacy Filter hit #1 on Hugging Face with 244,000 downloads, spreading infostealer malware to Windows users.
Fake OpenAI repository on Hugging Face pushes infostealer malware
A malicious Hugging Face repository that reached the platform's trending list impersonated OpenAI's "Privacy Filter" project to deliver information-stealing malware to Windows users.
Part of the PlainSec briefing for 2026-05-13