# Fake OpenAI Privacy Filter Repo Takes #1 on Hugging Face: 244K Downloads of Sophisticated Supply Chain Attack


A malicious repository masquerading as OpenAI's legitimate Privacy Filter project exploited open-source trust mechanisms to distribute a multi-stage information stealer on Hugging Face, one of the internet's most widely used machine learning model repositories. The attack successfully ranked #1 in the platform's trending list within 18 hours, accumulating approximately 244,000 downloads before being disabled.


## The Threat


The compromised repository, named Open-OSS/privacy-filter, executed a sophisticated supply chain attack that combined typosquatting, social engineering, and obfuscated malware delivery to target Windows, Linux, and macOS systems. The attack was designed to harvest sensitive information including cryptocurrency wallets, Discord credentials, browser data, system metadata, and files containing wallet seed phrases and configuration data.


According to analysis by the HiddenLayer Research Team, the malicious project:


  • Copied OpenAI's legitimate model card verbatim to appear authentic
  • Used nearly identical naming to confuse users between the real openai/privacy-filter and the fake Open-OSS/privacy-filter
  • Distributed a four-stage malware loader that established a chain of execution before deploying the final infostealer payload
  • Artificially inflated engagement metrics (likes and downloads) within the first hours to increase perceived legitimacy

  • The attack claimed an estimated 667 likes and topped Hugging Face's trending page, suggesting coordinated or bot-amplified engagement designed to accelerate user downloads before discovery.


    ## Background and Context


    Privacy Filter Context


    OpenAI released the legitimate Privacy Filter model in April 2026 as an open-weight tool designed to detect and redact personally identifiable information (PII) in unstructured text. The model targets legitimate use cases—helping organizations protect sensitive data in logs, customer communications, and AI training datasets—making it an attractive target for impersonation.


    The timing of the attack is significant: emerging tools in the AI security space often receive rapid adoption from developers eager to implement privacy safeguards. Threat actors exploited this urgency to accelerate downloads of the malicious variant.


    Hugging Face as an Attack Surface


    Hugging Face hosts over 1 million open-source models and datasets and has become the de facto marketplace for machine learning projects. The platform's community-driven governance model—while fostering innovation—creates visibility and trust that adversaries can weaponize. Users downloading trending models often bypass rigorous verification, trusting community engagement metrics and platform curation as indicators of legitimacy.


    ## Technical Details


    The malware delivery chain involved four distinct execution stages designed to evade detection and maximize information exfiltration:


    ### Stage 1: Initial Loader (loader.py / start.bat)


    The malicious repository included instructions to clone the project and execute either:

  • start.bat for Windows users
  • loader.py for Linux/macOS users

  • The Python loader immediately:

  • Disabled SSL verification to allow unsigned connections
  • Decoded a Base64-encoded URL hosted on JSON Keeper (a public JSON paste service)
  • Retrieved a command from the JSON Keeper service for dynamic payload switching

  • This design allowed attackers to modify payloads without updating the repository, enabling rapid pivoting if initial payloads were detected.


    ### Stage 2: Privilege Escalation & Defense Evasion


    The PowerShell command downloaded from JSON Keeper fetched a batch script from api.eth-fastscan[.]org and executed it via cmd.exe.


    The batch script then:

  • Triggered a User Account Control (UAC) prompt to escalate privileges
  • Configured Microsoft Defender Antivirus exclusions to bypass Windows security scanning
  • Downloaded the next-stage binary from the same remote domain
  • Created a scheduled task to execute a PowerShell launcher script

  • | Evasion Technique | Purpose |

    |---|---|

    | SSL Verification Disabled | Allow unsigned/expired certificate connections |

    | Base64 Encoding | Obfuscate command-and-control URLs |

    | UAC Elevation | Gain SYSTEM-context execution |

    | Defender Exclusions | Bypass on-device antivirus detection |

    | JSON Keeper Dead Drop | Dynamic payload switching without repo modification |


    ### Stage 3: Final Payload Execution


    Once the scheduled task launched, the malware waited two seconds before self-destructing—ensuring the execution chain couldn't be easily reversed by forensic analysis or security tools.


    The final-stage infostealer then:

  • Disabled AMSI (Antimalware Scan Interface) to prevent behavioral detection
  • Disabled ETW (Event Tracing for Windows) to prevent activity logging
  • Checked for debugger/sandbox environments and terminated if detected
  • Verified non-virtual-machine execution to avoid honeypots

  • ### Stage 4: Data Exfiltration


    The stealer targeted multiple high-value data sources:


  • Cryptocurrency wallets (wallet.dat files, seed phrases, private keys)
  • Browser data (Chromium and Gecko-based browsers including Chrome, Firefox, Edge)
  • Discord credentials (tokens, authentication data)
  • System metadata (hardware identification, OS version, installed software)
  • File artifacts (FileZilla configurations, SSH keys, configuration files)
  • Screenshots (capturing visible desktop content)

  • Stolen data was exfiltrated in JSON format to the domain recargapopular[.]com, allowing attackers to aggregate victim data programmatically.


    ### Attribution & Scope


    HiddenLayer identified six additional repositories using the same Python loader and infrastructure:

  • anthfu/Bonsai-8B-gguf
  • anthfu/Qwen3.6-35B-A3B-APEX-GGUF
  • anthfu/DeepSeek-V4-Pro
  • anthfu/Qwopus-GLM-18B-Merged-GGUF
  • anthfu/Qwen3.6-35B-A3B-Claude-4.6-Opus-Reasoning-Distilled-GGUF
  • anthfu/supergemma4-26b-uncensored-gguf-v2

  • The anthfu accounts suggest an organized campaign targeting multiple popular open-source models with identical attack infrastructure.


    ## Implications


    Supply Chain Risk Elevation


    This attack demonstrates that open-source model repositories are now high-value targets for sophisticated threat actors. Unlike traditional software supply chain attacks (which may compromise build systems or dependencies), model repository attacks exploit user trust in community curation and platform metrics.


    Cryptocurrency Targets


    The focus on cryptocurrency wallets, seed phrases, and browser extensions indicates adversaries are prioritizing theft from users with measurable digital assets. A single compromised wallet containing significant cryptocurrency holdings represents a six-to-seven-figure payday for attackers.


    Metrics Gaming as Attack Vector


    The artificial inflation of likes and downloads within 18 hours suggests either:

  • Coordinated bot networks that amplify malicious projects
  • Paid engagement services accessible to threat actors
  • Exploitable platform algorithms that reward rapid engagement without verification

  • Platform trust models that rely on community metrics are inherently vulnerable to adversary manipulation.


    Windows as Primary Target


    While the loader supported Linux and macOS, the sophisticated multi-stage Windows payload indicates primary targeting of Windows users—likely reflecting the largest overlap between cryptocurrency holders and Windows systems.


    ## Recommendations


    ### For Individual Users


  • Verify repository ownership before downloading models: check domain registration, author history, and review comments for warnings
  • Never run unfamiliar scripts (start.bat, loader.py) without reviewing their contents
  • Use isolated environments for untested models: deploy in VMs or sandboxed containers separate from production systems and personal wallets
  • Disable automatic execution: require explicit confirmation before running setup scripts
  • Monitor your system: watch for unexpected scheduled tasks, Defender exclusions, and outbound connections to unfamiliar domains

  • ### For Organizations


  • Audit Hugging Face downloads: identify which models are in production or development environments
  • Implement model verification workflows: require security review before any open-source model deployment
  • Monitor for indicators of compromise: search for scheduled tasks to api.eth-fastscan[.]org and recargapopular[.]com; check for unexpected Defender exclusions
  • Enforce Windows security controls: ensure AMSI, ETW, and UAC cannot be disabled without administrative intervention
  • Rotate credentials: if any systems downloaded this repository, treat as potential compromise and rotate authentication credentials

  • ### For Hugging Face


  • Implement stricter verification for trending lists: require manual review before repositories reach trending status
  • Flag similar repository names: surface warnings when repository names closely match established projects
  • Require model card customization: detect verbatim model card duplication from legitimate sources
  • Implement file sandbox analysis: automatically execute suspicious loader scripts in sandboxed environments before allowing distribution

  • ## HackWire Analysis


    This attack reveals a critical gap in open-source security infrastructure. Hugging Face has enabled the democratization of machine learning, but the platform lacks supply chain governance comparable to npm, PyPI, or Docker Hub. Those ecosystems have implemented signing, verification, and automated malware scanning—protections largely absent from model repositories.


    What makes this incident noteworthy isn't the technical sophistication of the stealer itself (four-stage loaders are standard fare), but rather how trivially it exploited platform mechanics. Typosquatting works because users trust visual similarity and engagement metrics more than cryptographic verification. The attack succeeded not through zero-days or sophisticated evasion, but through social engineering at scale.


    The discovery of six additional malicious repositories under the same infrastructure suggests this isn't an opportunistic campaign but a sustained operation targeting the model ecosystem. If attackers can sustain four-figure download volumes per repository, the aggregate victim count across the entire campaign likely reaches tens of thousands.


    For defenders, this underscores an uncomfortable reality: supply chain trust is an asymmetric game. Legitimate projects must build trust over months or years; malicious ones can exploit that trust infrastructure once and vanish. The 18-hour window before Hugging Face disabled access means the damage was largely complete before detection. Future attacks will likely use throwaway infrastructure and account credentials, making attribution and takedown cycles increasingly futile.


    The real solution isn't faster takedowns—it's shifting to verification-first workflows. Organizations should assume that repositories can be compromised and treat model downloads with the same skepticism as dependency management: automated scanning, sandboxed execution, and behavioral monitoring before anything touches production systems.


    — HackWire Editorial


    ## Related Coverage


  • Read more in our [Malware](https://www.hackwire.news/category/malware) coverage
  • Cross-reference with [Supply Chain Attacks](https://www.hackwire.news/category/supply-chain) and [Threat Intelligence](https://www.hackwire.news/category/threat-intelligence)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)