logo

Trending Hugging Face Repo With 200K Downloads Spreads Windows Malware

ID: 753f3ded-bd58-5b1d-b368-0653de552c22

STIX ID: report--753f3ded-bd58-5b1d-b368-0653de552c22

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-05-11

Date Updated: 2026-05-11

Author: Mayura Kathir

...
...

A malicious Hugging Face repository (Open-OSS/privacy-filter) abused platform trust and trending mechanisms to distribute a multi-stage attack that used a Python loader to retrieve and execute a PowerShell payload, which downloaded a batch updater that deployed a Rust-based infostealer. The infostealer performs extensive credential and crypto-wallet theft, employs robust anti-analysis and persistence techniques (UAC elevation, Defender exclusions, scheduled task impersonating Microsoft Edge updater), and exfiltrates data to identified C2 domains; the report provides IoCs and recommends host reimaging and credential rotation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.