logo

Fake OpenAI Privacy Filter Repo Hits #1 on Hugging Face, Draws 244K Downloads

ID: 4798e091-e99f-5647-ad27-f7cb85163bde

STIX ID: report--4798e091-e99f-5647-ad27-f7cb85163bde

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2026-05-11

Date Updated: 2026-05-11

Author: [email protected] (The Hacker News)

...
...

A malicious Hugging Face repository typosquatted OpenAI's Privacy Filter model and distributed a multi-stage Rust-based information stealer to Windows users via a Python loader and start.bat; the attack used JSON Keeper as a dead-drop, PowerShell- and batch-based second-stage downloaders, scheduled tasks for one-shot SYSTEM execution, AMSI/ETW bypasses, and exfiltration to attacker-controlled domains. HiddenLayer found the repo reached #1 trending with ~244,000 downloads before removal, discovered six additional repositories using the same loader, and noted shared infrastructure linking the campaign to prior ValleyRAT activity and a suspected Silver Fox operator.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.