# Fake OpenAI Repository on Hugging Face Briefly Hosts Infostealer Malware, Reaches 244,000 Downloads
A sophisticated supply-chain attack exploited trust in the Hugging Face model repository platform this week, with researchers discovering a malicious repository impersonating OpenAI that distributed advanced infostealer malware to Windows users. The attack achieved notability by briefly ranking #1 on Hugging Face's trending list before the platform removed it following security researcher reports.
## The Threat: Typosquatting at Scale
On May 7, 2026, researchers at HiddenLayer, a firm specializing in AI/ML security, identified a malicious repository using the name Open-OSS/privacy-filter — a subtle impersonation of OpenAI's legitimate "Privacy Filter" project. The repository closely mimicked OpenAI's model card, copying descriptions and metadata nearly verbatim to establish credibility within the AI development community.
Before removal, the repository accumulated 244,000 downloads and attracted approximately 667 accounts that "liked" the malicious model — though HiddenLayer notes that the vast majority of these interactions appear to be artificially generated, and download counts may have been artificially inflated through automated means.
The malicious repository hosted a Python loader script (loader.py) disguised as legitimate AI model code, but the underlying payload triggered a multi-stage attack chain that ultimately delivered a Rust-based information-stealing trojan to compromised systems.
## Background and Context: Hugging Face as an Attack Vector
Hugging Face has emerged as a critical infrastructure point for AI research and development, hosting over 500,000 models, datasets, and machine learning tools. The platform's open nature and high trust level within the developer community make it an attractive target for sophisticated threat actors seeking to distribute malware under the guise of legitimate projects.
This is not the first time Hugging Face has been weaponized. In previous incidents, threat actors have hosted malicious models exploiting the platform's reputation and the community's assumption that popular repositories are safe. However, this latest campaign represents a notable escalation in:
The attack underscores a critical vulnerability in supply-chain security: legitimate distribution channels are only as secure as the verification mechanisms that protect them. When a repository impersonates a trusted vendor closely enough, users may skip security checks.
## Technical Details: The Attack Chain Breakdown
The malicious loader.py script demonstrates careful engineering to bypass detection:
### Stage 1: Deceptive Loading Script
The Python script begins with legitimate-looking AI model initialization code, complete with imports and configuration parameters that suggest a real AI project. However, hidden within the initialization logic:
### Stage 2: PowerShell Command Execution
The fetched JSON contains a PowerShell script executed invisibly (hidden window, no user interaction):
start.bat) from the attacker's infrastructure### Stage 3: Privilege Escalation and Defense Evasion
The batch file (start.bat) performs sophisticated post-exploitation:
sefirah) — a Rust-compiled infostealer### Stage 4: Information Exfiltration
The final Rust-based infostealer targets a comprehensive range of sensitive data:
| Data Category | Specific Targets |
|---|---|
| Browser Data | Chromium & Gecko-based browsers (Chrome, Firefox, Edge, Brave) — cookies, saved passwords, encryption keys, browsing history, session tokens |
| Communication Platforms | Discord tokens, local message databases, master encryption keys |
| Cryptocurrency | Wallet applications, browser extensions, seed phrases, private keys |
| Remote Access | SSH keys, FTP credentials, VPN configuration files, FileZilla credentials |
| System Information | Multi-monitor screenshots, system details, environment variables |
All stolen data is compressed and exfiltrated to a command-and-control server at recargapopular[.]com.
## Anti-Analysis and Evasion Features
The malware includes extensive defensive capabilities designed to evade security research and sandboxed environments:
These protections significantly hamper analysis efforts and suggest a threat actor with experience evading security vendor detection systems.
## Scale, Attribution, and Related Campaigns
The actual number of victims remains unclear. While the repository shows 244,000 downloads, HiddenLayer's analysis suggests significant artificial inflation through bot networks.
More concerning, researchers identified overlaps between this campaign and other ongoing threat operations, including:
This pattern suggests either:
1. A single threat actor running multiple parallel campaigns
2. A malware-as-a-service (MaaS) operation selling the loader infrastructure to other criminals
3. A coordinated group sharing tools and techniques
## Recommendations for Users and Organizations
For users who downloaded from the malicious repository:
Immediate Actions (Critical):
Investigation and Monitoring:
Prevention for Development Teams:
## HackWire Analysis
This incident exemplifies a critical vulnerability in modern software development culture: trust misplaced in platforms rather than in cryptographic verification. Hugging Face's security measures are reasonable, but they operate on the assumption that humans will validate repository authenticity — an assumption that fails when a repository is well-enough crafted.
The deeper pattern here is the maturation of supply-chain attacks. Rather than compromising legitimate projects (which triggers immediate suspicion when maintainers notice), sophisticated threat actors now invest in creating convincing fakes that exploit the platform's algorithmic amplification. A repository that reaches the trending list gains exponential visibility — exactly what happened here before removal.
What's particularly revealing is the overlap with npm typosquatting campaigns. This suggests threat actors are running parallel operations across different package ecosystems simultaneously, likely capitalizing on the fact that defenders are fragmented across security domains. A developer might be security-conscious on npm but less vigilant on Hugging Face, or vice versa.
The bot-inflated download and like counts reveal another weakness: platforms optimize for engagement metrics, but those same metrics can be gamed by attackers to create false legitimacy. A repository with 244,000 downloads appearing in trending lists creates social proof that guides user behavior — exactly what threat actors exploit.
For defenders, the lesson is uncomfortable: you cannot trust any centralized platform's authenticity signals at face value, regardless of the platform's reputation. Cryptographic verification (code signing, hash verification, signature checks) remains the only reliable assurance mechanism. Community platforms are valuable, but they are not substitutes for actual security practices.
— HackWire Editorial
## Related Coverage