A fake OpenAI repository has taken top spot on Hugging Face — but all it does is push infostealer malware



  • Attackers typosquatted an OpenAI repo on HuggingFace, distributing an infostealer disguised as a “privacy filter” model
  • The malware disabled SSL checks, escalated privileges, and deployed the sefirah payload to steal credentials, crypto wallets, and system data
  • The fake repo hit 244,000 downloads and briefly topped HuggingFace rankings before removal, with other linked malicious repos also taken down

Cybercriminals were able tp spoof OpenAI products to distribute an infostealer malwar to more than 240,000 computers before being spotted and eliminated, experts have warned.

Security researchers HiddenLayer said they spotted a new repository on HuggingFace called Open-OSS/privacy-filter.

https://cdn.mos.cms.futurecdn.net/PAztEScphfxGJfYno5NjrL-2560-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img