Fake OpenAI repository on Hugging Face pushes infostealer malware
ID: e44aa043-26bd-55e6-956a-76b9d85ba21c
STIX ID: report--e44aa043-26bd-55e6-956a-76b9d85ba21c
Feed Name: Bleeping Computer
HiddenLayer discovered a malicious Hugging Face repository that impersonated OpenAI's Privacy Filter, reached the platform's trending list, and delivered a Rust-based infostealer via a loader.py -> PowerShell chain; the malware collects browser data, Discord tokens, cryptocurrency wallets, SSH/FTP credentials and other sensitive files, exfiltrating them to recargapopular.com, and includes extensive anti-analysis and persistence techniques, while victim counts remain unclear and remediation guidance includes reimaging and rotating credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
