# Fake OpenAI Privacy Filter Repo Takes #1 on Hugging Face: 244K Downloads of Sophisticated Supply Chain Attack
A malicious repository masquerading as OpenAI's legitimate Privacy Filter project exploited open-source trust mechanisms to distribute a multi-stage information stealer on Hugging Face, one of the internet's most widely used machine learning model repositories. The attack successfully ranked #1 in the platform's trending list within 18 hours, accumulating approximately 244,000 downloads before being disabled.
## The Threat
The compromised repository, named Open-OSS/privacy-filter, executed a sophisticated supply chain attack that combined typosquatting, social engineering, and obfuscated malware delivery to target Windows, Linux, and macOS systems. The attack was designed to harvest sensitive information including cryptocurrency wallets, Discord credentials, browser data, system metadata, and files containing wallet seed phrases and configuration data.
According to analysis by the HiddenLayer Research Team, the malicious project:
openai/privacy-filter and the fake Open-OSS/privacy-filterThe attack claimed an estimated 667 likes and topped Hugging Face's trending page, suggesting coordinated or bot-amplified engagement designed to accelerate user downloads before discovery.
## Background and Context
Privacy Filter Context
OpenAI released the legitimate Privacy Filter model in April 2026 as an open-weight tool designed to detect and redact personally identifiable information (PII) in unstructured text. The model targets legitimate use cases—helping organizations protect sensitive data in logs, customer communications, and AI training datasets—making it an attractive target for impersonation.
The timing of the attack is significant: emerging tools in the AI security space often receive rapid adoption from developers eager to implement privacy safeguards. Threat actors exploited this urgency to accelerate downloads of the malicious variant.
Hugging Face as an Attack Surface
Hugging Face hosts over 1 million open-source models and datasets and has become the de facto marketplace for machine learning projects. The platform's community-driven governance model—while fostering innovation—creates visibility and trust that adversaries can weaponize. Users downloading trending models often bypass rigorous verification, trusting community engagement metrics and platform curation as indicators of legitimacy.
## Technical Details
The malware delivery chain involved four distinct execution stages designed to evade detection and maximize information exfiltration:
### Stage 1: Initial Loader (loader.py / start.bat)
The malicious repository included instructions to clone the project and execute either:
The Python loader immediately:
This design allowed attackers to modify payloads without updating the repository, enabling rapid pivoting if initial payloads were detected.
### Stage 2: Privilege Escalation & Defense Evasion
The PowerShell command downloaded from JSON Keeper fetched a batch script from api.eth-fastscan[.]org and executed it via cmd.exe.
The batch script then:
| Evasion Technique | Purpose |
|---|---|
| SSL Verification Disabled | Allow unsigned/expired certificate connections |
| Base64 Encoding | Obfuscate command-and-control URLs |
| UAC Elevation | Gain SYSTEM-context execution |
| Defender Exclusions | Bypass on-device antivirus detection |
| JSON Keeper Dead Drop | Dynamic payload switching without repo modification |
### Stage 3: Final Payload Execution
Once the scheduled task launched, the malware waited two seconds before self-destructing—ensuring the execution chain couldn't be easily reversed by forensic analysis or security tools.
The final-stage infostealer then:
### Stage 4: Data Exfiltration
The stealer targeted multiple high-value data sources:
Stolen data was exfiltrated in JSON format to the domain recargapopular[.]com, allowing attackers to aggregate victim data programmatically.
### Attribution & Scope
HiddenLayer identified six additional repositories using the same Python loader and infrastructure:
anthfu/Bonsai-8B-ggufanthfu/Qwen3.6-35B-A3B-APEX-GGUFanthfu/DeepSeek-V4-Proanthfu/Qwopus-GLM-18B-Merged-GGUFanthfu/Qwen3.6-35B-A3B-Claude-4.6-Opus-Reasoning-Distilled-GGUFanthfu/supergemma4-26b-uncensored-gguf-v2The anthfu accounts suggest an organized campaign targeting multiple popular open-source models with identical attack infrastructure.
## Implications
Supply Chain Risk Elevation
This attack demonstrates that open-source model repositories are now high-value targets for sophisticated threat actors. Unlike traditional software supply chain attacks (which may compromise build systems or dependencies), model repository attacks exploit user trust in community curation and platform metrics.
Cryptocurrency Targets
The focus on cryptocurrency wallets, seed phrases, and browser extensions indicates adversaries are prioritizing theft from users with measurable digital assets. A single compromised wallet containing significant cryptocurrency holdings represents a six-to-seven-figure payday for attackers.
Metrics Gaming as Attack Vector
The artificial inflation of likes and downloads within 18 hours suggests either:
Platform trust models that rely on community metrics are inherently vulnerable to adversary manipulation.
Windows as Primary Target
While the loader supported Linux and macOS, the sophisticated multi-stage Windows payload indicates primary targeting of Windows users—likely reflecting the largest overlap between cryptocurrency holders and Windows systems.
## Recommendations
### For Individual Users
### For Organizations
api.eth-fastscan[.]org and recargapopular[.]com; check for unexpected Defender exclusions### For Hugging Face
## HackWire Analysis
This attack reveals a critical gap in open-source security infrastructure. Hugging Face has enabled the democratization of machine learning, but the platform lacks supply chain governance comparable to npm, PyPI, or Docker Hub. Those ecosystems have implemented signing, verification, and automated malware scanning—protections largely absent from model repositories.
What makes this incident noteworthy isn't the technical sophistication of the stealer itself (four-stage loaders are standard fare), but rather how trivially it exploited platform mechanics. Typosquatting works because users trust visual similarity and engagement metrics more than cryptographic verification. The attack succeeded not through zero-days or sophisticated evasion, but through social engineering at scale.
The discovery of six additional malicious repositories under the same infrastructure suggests this isn't an opportunistic campaign but a sustained operation targeting the model ecosystem. If attackers can sustain four-figure download volumes per repository, the aggregate victim count across the entire campaign likely reaches tens of thousands.
For defenders, this underscores an uncomfortable reality: supply chain trust is an asymmetric game. Legitimate projects must build trust over months or years; malicious ones can exploit that trust infrastructure once and vanish. The 18-hour window before Hugging Face disabled access means the damage was largely complete before detection. Future attacks will likely use throwaway infrastructure and account credentials, making attribution and takedown cycles increasingly futile.
The real solution isn't faster takedowns—it's shifting to verification-first workflows. Organizations should assume that repositories can be compromised and treat model downloads with the same skepticism as dependency management: automated scanning, sandboxed execution, and behavioral monitoring before anything touches production systems.
— HackWire Editorial
## Related Coverage