Fake OpenAI Privacy Filter Repo Hits #1 on Hugging Face, Delivers Infostealer

A malicious Hugging Face repository impersonating OpenAI’s Privacy Filter model reached #1 trending and logged about 244,000 downloads in under 18 hours before removal. HiddenLayer said about 657 of the repo’s 667 likes matched bot-like naming patterns. The campaign delivered a multi-stage infostealer on Windows that harvested browser passwords, Discord tokens, crypto wallet keys, and SSH credentials and sent them to attacker-controlled servers.

This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pin