www.hiddenlayer.com Malware Discovered in Typosquatted Hugging Face Repository Impersonating OpenAI
Article Content
- •A malicious repository on Hugging Face impersonated OpenAI's Privacy Filter, reaching 244,000 downloads.
- •The malware executed via a loader.py script that fetched infostealer payloads on Windows systems.
- •Users are urged to reimage affected machines and rotate all stored credentials immediately.
On May 7, 2026, researchers identified malware in the Hugging Face repository Open-OSS/privacy-filter, which had impersonated OpenAI's legitimate Privacy Filter project. The malicious repository reached #1 on the platform, accumulating 244,000 downloads before being removed. It contained a loader.py file that executed infostealer malware on Windows systems. The attack involved typosquatting, copying model cards, and using a command-and-control channel to fetch and execute malicious payloads. Users who interacted with the repository are advised to treat their systems as compromised and take immediate security measures, including reimaging affected machines and rotating credentials. The malware features extensive anti-analysis capabilities, complicating detection efforts. The incident highlights ongoing threats to AI model repositories despite existing security measures.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (16)
Following this threat?
Track WinOS 4.0 Implant in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…