Fake OpenAI Privacy Filter Repo Hits #1 on Hugging Face, Draws 244K Downloads
ID: 4798e091-e99f-5647-ad27-f7cb85163bde
STIX ID: report--4798e091-e99f-5647-ad27-f7cb85163bde
Feed Name: The Hacker News
A malicious Hugging Face repository typosquatted OpenAI's Privacy Filter model and distributed a multi-stage Rust-based information stealer to Windows users via a Python loader and start.bat; the attack used JSON Keeper as a dead-drop, PowerShell- and batch-based second-stage downloaders, scheduled tasks for one-shot SYSTEM execution, AMSI/ETW bypasses, and exfiltration to attacker-controlled domains. HiddenLayer found the repo reached #1 trending with ~244,000 downloads before removal, discovered six additional repositories using the same loader, and noted shared infrastructure linking the campaign to prior ValleyRAT activity and a suspected Silver Fox operator.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
