Attackers Use Fake OpenAI Model to Push Credential-Stealing Malware
ID: a6c846a7-1edd-56f8-9e93-3d12702655d0
STIX ID: report--a6c846a7-1edd-56f8-9e93-3d12702655d0
Feed Name: Security Boulevard
A fraudulent Hugging Face repository posing as OpenAI's Privacy Filter briefly amassed roughly 244,000 downloads and distributed a malware chain that disabled SSL verification and Windows security controls, fetched remote instructions, executed PowerShell payloads, and deployed a Rust-based infostealer to harvest browser credentials, wallets, Discord tokens, FTP data and local system information; researchers linked overlapping infrastructure to prior malicious packages and to tooling associated with ValleyRAT/Silver Fox, and recommended rebuilding compromised systems, rotating credentials, invalidating sessions, and moving crypto assets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
