Trending Hugging Face Repo With 200k Downloads Executes Malware on Windows Machines
ID: 75396d38-cf07-575a-b1e9-c7453ce20fe3
STIX ID: report--75396d38-cf07-575a-b1e9-c7453ce20fe3
Feed Name: cybersecurityNews.com
**Executive Summary:** A malicious Hugging Face repository (Open-OSS/privacy-filter) posed as a privacy-filter tool and delivered a multi-stage Windows malware chain: a Python loader and PowerShell batch downloader installed a Rust-based infostealer that evaded analysis, collected browser credentials, SSH keys, VPN/FTP data, wallet files, and screenshots, and exfiltrated stolen data to a command-and-control server; the report includes IoCs, related repositories, persistence details (MicrosoftEdgeUpdateTaskCore), and remediation guidance (isolate affected hosts, rotate/revoke credentials and tokens, reimage).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
