Popular Hugging Face Repo With 200K Downloads Executes Windows Malware
ID: 2df3fb02-b7b9-55c4-95c7-ff5f0713bdba
STIX ID: report--2df3fb02-b7b9-55c4-95c7-ff5f0713bdba
Feed Name: Cyber Press
**Executive Summary:** A trending Hugging Face repository (Open-OSS/privacy-filter) with over 200,000 downloads is being used to distribute a Windows credential‑harvesting infostealer; malicious scripts disable SSL verification, fetch updated PowerShell commands from a public JSON paste, run a second-stage downloader that installs the payload, checks for admin rights, and adds Microsoft Defender exclusions. Researchers linked multiple repositories from the same user and shared infrastructure with prior npm typosquatting attacks, provided C2 domains and IOC entries, and advise full host reimages, credential rotation, network egress blocking, and threat hunting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
