Close Menu
Tech Nova Mindset – Empower Innovation and Forward Thinking

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    A US-China AI Hotline Won’t Be Ready For a While

    September 23, 2026

    A congressional representative just proposed killing America’s border tower program

    September 23, 2026

    Parents Guide Kids to Top Engineering Skills In AI Age

    September 23, 2026
    Facebook X (Twitter) Instagram
    Trending
    • A US-China AI Hotline Won’t Be Ready For a While
    • A congressional representative just proposed killing America’s border tower program
    • Parents Guide Kids to Top Engineering Skills In AI Age
    • Meta’s Muse AI Assistant Rolled Out With a Serious Security Flaw
    • The Download: India’s smart glasses menace and AI’s trillion-dollar gamble
    • AT&T Is Automating Away Jobs—and Its Old Telecom Empire
    • Smart glasses are already causing havoc in India
    • Viture’s Vonder Glasses Are Meant to Map Your Mind
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    • Home
    • Gadgets
    • Reviews
    • Tech News
    • Future Tech
    • AI & Robotics
    • How-To Guides
    • More
      • Cybersecurity
      • Startups & Innovation
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    Home»Cybersecurity»Fake OpenAI repository on Hugging Face pushes infostealer malware
    Cybersecurity

    Fake OpenAI repository on Hugging Face pushes infostealer malware

    kirklandc008@gmail.comBy kirklandc008@gmail.comMay 9, 2026No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Fake OpenAI repository on Hugging Face pushes infostealer malware
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A malicious Hugging Face repository that reached the platform’s trending list impersonated OpenAI’s “Privacy Filter” project to deliver information-stealing malware to Windows users.

    The repository briefly reached #1 on Hugging Face and accumulated 244,000 downloads before the platform responded to reports and removed it.

    The Hugging Face platform lets developers and researchers share AI models, datasets, and machine learning (ML) tools. Models are pre-trained AI systems hosted on the platform comprising weight files, configuration, and code.

    Researchers at HiddenLayer, a company focused on safeguarding AI and ML models against attacks, discovered the campaign on May 7, after noticing a malicious repository named Open-OSS/privacy-filter.

    “The repository had typosquatted OpenAI’s legitimate Privacy Filter release, copied its model card nearly verbatim, and shipped a loader.py file that fetches and executes infostealer malware on Windows machines,” the researchers explain.

    Instructions from the malicious repository
    Source: HiddenLayer

    The ‘loader.py’ Python script included fake AI-related code to appear harmless, but in the background, it disabled SSL verification, decoded a base64 URL pointing to an external resource, and then fetched and executed a JSON payload containing a PowerShell command.

    The command, which is executed in an invisible window, downloads a batch file (start.bat) that performs privilege escalation, downloads the final payload (sefirah), adds it to Microsoft Defender’s exclusions for it, and executes it.

    The final payload is a Rust-based infostealer that targets the following sensitive data:

    • Browser data from Chromium- and Gecko-based browsers (e.g., cookies, saved passwords, encryption keys, browsing data, session tokens)
    • Discord tokens, local databases, and master keys
    • Cryptocurrency wallets and wallet browser extensions
    • SSH, FTP, and VPN credentials and configuration files, including FileZilla
    • Sensitive local files and wallet seeds/keys
    • System information
    • Multi-monitor screenshots

    The stolen data is compressed and exfiltrated to a command-and-control (C2) server at recargapopular[.]com.

    HiddenLayer highlights the malware’s extensive anti-analysis features, which include checks for virtual machines, sandboxes, debuggers, and analysis tools, all with the purpose of evading analysis systems.

    The exact number of victims in this incident is unclear, and the researchers note that the vast majority of the 667 accounts that liked the malicious repository on Hugging Face appear to be auto-generated. Additionally, the 244,000 download count may have been artificially inflated.

    By examining those, the researchers uncovered other repositories that used the same malicious loader infrastructure. HiddenLayer researchers also noticed overlaps with an npm typosquatting campaign distributing the WinOS 4.0 implant.

    Users who downloaded files from the malicious repository are advised to reimage the machine, rotate all stored credentials, replace cryptocurrency wallets and seed phrases, and invalidate browser sessions and tokens.

    Threat actors have abused Hugging Face in the past to host malicious models, despite the platform’s security measures.

    AI chained four zero-days into one exploit that bypassed both renderer and OS sandboxes. A wave of new exploits is coming.

    At the Autonomous Validation Summit (May 12 & 14), see how autonomous, context-rich validation finds what’s exploitable, proves controls hold, and closes the remediation loop.

    Claim Your Spot

    Face Fake Hugging infostealer malware OpenAI Pushes repository
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    kirklandc008@gmail.com
    • Website

    Related Posts

    OpenAI Creates a New Framework to Disclose Bad AI Behavior

    September 17, 2026

    AI models need more data about biology, and OpenAI is paying to create it

    September 16, 2026

    OpenAI Claims Another Huge Mathematical Result Amid Fights Over Credit, Ethics, and Privacy

    September 12, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Nothing CEO says phone prices are going to keep going up

    June 12, 20267 Views

    The best VPN routers of 2026: Expert tested and reviewed

    June 14, 20263 Views

    Google DeepMind Plans to Track AGI Progress With These 10 Traits of General Intelligence

    March 21, 20263 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Recent Posts
    • A US-China AI Hotline Won’t Be Ready For a While
    • A congressional representative just proposed killing America’s border tower program
    • Parents Guide Kids to Top Engineering Skills In AI Age
    • Meta’s Muse AI Assistant Rolled Out With a Serious Security Flaw
    • The Download: India’s smart glasses menace and AI’s trillion-dollar gamble

    A US-China AI Hotline Won’t Be Ready For a While

    September 23, 2026

    A congressional representative just proposed killing America’s border tower program

    September 23, 2026

    Parents Guide Kids to Top Engineering Skills In AI Age

    September 23, 2026

    Meta’s Muse AI Assistant Rolled Out With a Serious Security Flaw

    September 23, 2026
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 TechNovaMindset. Designed by By Pro.

    Type above and press Enter to search. Press Esc to cancel.