Malicious Hugging Face Repository Typosquats OpenAI
ID: 2595e3c1-4195-5082-95f1-fd363fa09c89
STIX ID: report--2595e3c1-4195-5082-95f1-fd363fa09c89
Feed Name: Infosecurity Magazine (News)
Security researchers identified a typosquatted Hugging Face repository (Open-OSS/privacy-filter) distributing a Rust-based infostealer via a loader script (start.bat / python loader.py). The malware, which appeared to have artificially inflated popularity, drops a credential-harvesting executable that steals browser passwords, session cookies, Discord tokens, crypto wallets, Telegram sessions and more while employing sandbox/VM/debugger checks and attempting to disable AMSI/ETW; the vendor advises treating affected hosts as fully compromised, wiping them, rotating all credentials and moving crypto funds to clean devices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
