Malware Discovered in Typosquatted Hugging Face Repository Impersonating OpenAI

Malware Discovered in Typosquatted Hugging Face Repository Impersonating OpenAI

First seen 9 May 2026, 15:09 UTC BleepingcomputerRescanaLetsdatascienceGbhackersCsoonline+10 88% similarity 72.0

Article Content

Browse articles
ThreatCluster

On May 7, 2026, researchers identified malware in the Hugging Face repository Open-OSS/privacy-filter, which had impersonated OpenAI's legitimate Privacy Filter project. The malicious repository reached #1 on the platform, accumulating 244,000 downloads before being removed. It contained a loader.py file that executed infostealer malware on Windows systems. The attack involved typosquatting, copying model cards, and using a command-and-control channel to fetch and execute malicious payloads. Users who interacted with the repository are advised to treat their systems as compromised and take immediate security measures, including reimaging affected machines and rotating credentials. The malware features extensive anti-analysis capabilities, complicating detection efforts. The incident highlights ongoing threats to AI model repositories despite existing security measures.

Key Points: • A malicious repository on Hugging Face impersonated OpenAI's Privacy Filter, reaching 244,000 downloads. • The malware executed via a loader.py script that fetched infostealer payloads on Windows systems. • Users are urged to reimage affected machines and rotate all stored credentials immediately.

ThreatCluster AI

Timeline

2026-05-07
Malware identified in Hugging Face repository
Researchers found malicious code in Open-OSS/privacy-filter, which had impersonated OpenAI's Privacy Filter project.
HiddenLayer
2026-05-07
Repository removed from Hugging Face
Hugging Face removed the malicious repository after it reached #1 and was reported by researchers.
BleepingComputer
2026-05-09
Security advisory issued for affected users
Users who downloaded from the repository are advised to reimage machines and rotate credentials due to potential compromise.
BleepingComputer

Community

Browse all →