Malicious Repository Impersonates OpenAI Model on Hugging Face
- A fake Hugging Face repository mimicking OpenAI’s Privacy Filter model reached the top trending spot with about 244,000 downloads and 667 likes in less than a day.
- The repository contained malware that stole browser passwords, crypto wallet keys, Discord tokens, and SSH credentials from Windows systems.
- HiddenLayer identified six additional malicious repositories using similar tactics under another account named “anthfu.”
This incident highlights a significant security threat to AI developers through supply chain attacks by impersonating popular models and manipulating trending algorithms. Developers are advised to verify the authenticity of repositories before downloading.
The compromised repository has been removed, but users who downloaded it should consider their devices compromised and take immediate action to secure their information and assets. (Source)