• About
  • Advertise
  • Privacy & Policy
  • Contact
Vidianews
  • Home
  • Entertainment
    • All
    • Gaming
    • Movie
    elsie-hewitt-celebrates-her-first-mother’s-day-solo-amid-pete-davidson-rift

    Elsie Hewitt Celebrates Her First Mother’s Day Solo Amid Pete Davidson Rift

    streamer-chud-the-builder-arrested-after-scene-at-nashville-steakhouse,-cops-say

    Streamer Chud The Builder arrested after scene at Nashville Steakhouse, cops say

    6-horror-books-better-than-the-shining-by-stephen-king

    6 Horror Books Better Than The Shining by Stephen King

    J.

    pentagon-declassifies-more-ufo-sightings-to-skeptical-crowd

    Pentagon Declassifies More UFO Sightings To Skeptical Crowd

    taylor-swift-reportedly-plans-major-wedding-move-due-to-growing-security-concerns-ahead-of-big-day

    Taylor Swift reportedly plans major wedding move due to growing security concerns ahead of big day

  • Sports
  • Tech
    • All
    • Gadget
    • Startup
    what

    What

    a-fake-openai-repository-has-taken-the-top-spot-on-hugging-face-–-but-it’s-just-spreading-infostealer-malware

    A fake OpenAI repository has taken the top spot on Hugging Face – but it’s just spreading infostealer malware

    AI monitors your every move on the road. These state laws push back

    Amazon is being sued over Fire TV sticks that stopped working. Here’s what you need to know

    Papa Johns is launching drone delivery, but not for pizza

    prepare-for-the-quiet-office-of-the-future-|-techcrunch

    Prepare for the quiet office of the future | TechCrunch

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
  • Lifestyle
    • All
    • Faith
    • Health
    • Travel
    was-mount-sinai’s-victory-in-physician-licensing-dispute-worth-it?-–-medcity-news

    Was Mount Sinai’s Victory in Physician Licensing Dispute Worth It? – MedCity News

    7-simple-faith-activities-for-moms-and-kids

    7 Simple Faith Activities for Moms and Kids

    spend-the-day-with-me-at-eden-rock-–-st-barths

    Spend the day with me at Eden Rock – St Barths

    pms-cures-that-no-one-talks-about-(but-should)

    PMS Cures That No One Talks About (But Should)

    it-takes-a-village

    It takes a village

    spring-pasta-recipes-that-prove-warmer-weather-makes-everything-taste-better

    Spring Pasta Recipes That Prove Warmer Weather Makes Everything Taste Better

    Trending Tags

    • Golden Globes
    • Game of Thrones
    • MotoGP 2017
    • eSports
    • Fashion Week
  • News
    • All
    • Business
    • Science

    Missing Wall Street: How a False Story Destroyed a Real Investor and Why the Truth Finally Wins – Insights Success

    French evacuee from ship hit by hantavirus tests positive, health minister says

    European markets open in mixed territory as Iran peace talks stall

    Arizona woman says she was hospitalized after getting a tattoo

    Trump and Xi should meet. Where are the tariffs between the United States and China?

    Thailand’s divisive former prime minister is out of prison, but is the Thaksin era over?

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Business
  • Politics
  • World
  • Review

    Apple May Discontinue Cheapest MacBook Neo Model Due to Rising DRAM Prices, Analyst Says

    OnePlus Nord: the phone that accidentally killed the OnePlus 8

    Flipkart Sale: Deals on iPhone 17, Apple Watch SE 3, Redmi Pad 2 Pro and other devices revealed

    How do you feel now that your Rs. Samsung Galaxy Fold is already obsolete?

    Apple AirPods with built-in cameras are expected to enter advanced testing and could launch soon

    14 reasons why OxygenOS on OnePlus Nord is better than stock Android

No Result
View All Result
  • Home
  • Entertainment
    • All
    • Gaming
    • Movie
    elsie-hewitt-celebrates-her-first-mother’s-day-solo-amid-pete-davidson-rift

    Elsie Hewitt Celebrates Her First Mother’s Day Solo Amid Pete Davidson Rift

    streamer-chud-the-builder-arrested-after-scene-at-nashville-steakhouse,-cops-say

    Streamer Chud The Builder arrested after scene at Nashville Steakhouse, cops say

    6-horror-books-better-than-the-shining-by-stephen-king

    6 Horror Books Better Than The Shining by Stephen King

    J.

    pentagon-declassifies-more-ufo-sightings-to-skeptical-crowd

    Pentagon Declassifies More UFO Sightings To Skeptical Crowd

    taylor-swift-reportedly-plans-major-wedding-move-due-to-growing-security-concerns-ahead-of-big-day

    Taylor Swift reportedly plans major wedding move due to growing security concerns ahead of big day

  • Sports
  • Tech
    • All
    • Gadget
    • Startup
    what

    What

    a-fake-openai-repository-has-taken-the-top-spot-on-hugging-face-–-but-it’s-just-spreading-infostealer-malware

    A fake OpenAI repository has taken the top spot on Hugging Face – but it’s just spreading infostealer malware

    AI monitors your every move on the road. These state laws push back

    Amazon is being sued over Fire TV sticks that stopped working. Here’s what you need to know

    Papa Johns is launching drone delivery, but not for pizza

    prepare-for-the-quiet-office-of-the-future-|-techcrunch

    Prepare for the quiet office of the future | TechCrunch

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
  • Lifestyle
    • All
    • Faith
    • Health
    • Travel
    was-mount-sinai’s-victory-in-physician-licensing-dispute-worth-it?-–-medcity-news

    Was Mount Sinai’s Victory in Physician Licensing Dispute Worth It? – MedCity News

    7-simple-faith-activities-for-moms-and-kids

    7 Simple Faith Activities for Moms and Kids

    spend-the-day-with-me-at-eden-rock-–-st-barths

    Spend the day with me at Eden Rock – St Barths

    pms-cures-that-no-one-talks-about-(but-should)

    PMS Cures That No One Talks About (But Should)

    it-takes-a-village

    It takes a village

    spring-pasta-recipes-that-prove-warmer-weather-makes-everything-taste-better

    Spring Pasta Recipes That Prove Warmer Weather Makes Everything Taste Better

    Trending Tags

    • Golden Globes
    • Game of Thrones
    • MotoGP 2017
    • eSports
    • Fashion Week
  • News
    • All
    • Business
    • Science

    Missing Wall Street: How a False Story Destroyed a Real Investor and Why the Truth Finally Wins – Insights Success

    French evacuee from ship hit by hantavirus tests positive, health minister says

    European markets open in mixed territory as Iran peace talks stall

    Arizona woman says she was hospitalized after getting a tattoo

    Trump and Xi should meet. Where are the tariffs between the United States and China?

    Thailand’s divisive former prime minister is out of prison, but is the Thaksin era over?

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Business
  • Politics
  • World
  • Review

    Apple May Discontinue Cheapest MacBook Neo Model Due to Rising DRAM Prices, Analyst Says

    OnePlus Nord: the phone that accidentally killed the OnePlus 8

    Flipkart Sale: Deals on iPhone 17, Apple Watch SE 3, Redmi Pad 2 Pro and other devices revealed

    How do you feel now that your Rs. Samsung Galaxy Fold is already obsolete?

    Apple AirPods with built-in cameras are expected to enter advanced testing and could launch soon

    14 reasons why OxygenOS on OnePlus Nord is better than stock Android

No Result
View All Result
Vidianews
No Result
View All Result
Home Tech

A fake OpenAI repository has taken the top spot on Hugging Face – but it’s just spreading infostealer malware

Ivan Mehta by Ivan Mehta
May 11, 2026
in Tech
0
a-fake-openai-repository-has-taken-the-top-spot-on-hugging-face-–-but-it’s-just-spreading-infostealer-malware

A fake OpenAI repository has taken the top spot on Hugging Face – but it’s just spreading infostealer malware

0
SHARES
0
VIEWS
Share on FacebookShare on Twitter
A robot standing thoughtfully in front of a giant digital screen with code on it
(Image credit: Getty Images)

  • Attackers typosquatted an OpenAI repository on HuggingFace, distributing an information stealer disguised as a ‘privacy filter’ template
  • The malware disabled SSL checks, escalated privileges and deployed the sefirah payload to steal credentials, crypto wallets and system data
  • The fake repository reached 244,000 downloads and briefly topped the HuggingFace rankings before its removal, while other related malicious repositories were also removed.

Cybercriminals successfully spoofed OpenAI products to distribute infostealer malware to more than 240,000 computers before being detected and eliminated, experts have warned.

Security researchers HiddenLayer said they spotted a new repository on HuggingFace called Open-OSS/privacy-filter.

The privacy filter repository is, according to HiddenLayer, a typosquatted version of the official version, accompanied by a model card copied “almost verbatim”. The loader.py file provided there fetches and runs an infostealer, they added.

Climb to the top

Before removing the infostealer, the malware first disabled SSL checking, decoded a base64 URL, and from it downloaded a JSON payload with a PowerShell command. This command, in turn, downloaded a batch file that escalated privileges, deployed the “sefirah” payload, added it to Microsoft Defender’s exclusion list, and then executed it.

The infostealer itself does what most infostealers do: scrapes data saved in browsers, exfiltrates Discord tokens, local databases and master keys, steals cryptocurrency wallet information, browser extension data, SSH, FTP, VPN credentials, as well as locally stored sensitive files. It can also recover screenshots, exfiltrate system information, etc.

The number of downloads on the fake repository is enormous: 244,000 downloads in just a few days.

However, this does not mean that every download results in an infection. BeepComputersays that download numbers may have been inflated and that the repository itself was “liked” by 667 auto-generated accounts. Yet even if everything was fake, the repository still managed to reach the top spot on Hugging Face for a brief moment, which certainly could have led to infections.

Sign up for the TechRadar Pro newsletter to get all the top news, opinions, features and tips your business needs to succeed!

However, by tracking the fake accounts, HiddenLayer was able to discover other, less efficient repositories that were also malicious and used the same infrastructure. All of these have since been removed from the platform.


Best Antivirus Software

Google logo on black background next to the text “Click to follow TechRadar”

Follow TechRadar on Google News And add us as your favorite source to get our news, reviews and expert opinions in your feeds.


Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). During his career, which spans more than a decade, he has written for numerous media outlets, including Al Jazeera Balkans. He has also hosted several modules on content writing for Represent Communications.

Related

Ivan Mehta

Ivan Mehta

Stay Connected

  • 99 Subscribers
  • Trending
  • Comments
  • Latest
european-markets-in-mixed-territory-after-a-positive-start

European markets in mixed territory after a positive start

January 26, 2026
daniel-duggan:-australian-citizen-and-former-us-navy-pilot-loses-extradition-appeal

Daniel Duggan: Australian citizen and former US Navy pilot loses extradition appeal

April 16, 2026
12-sweet-feminine-aesthetic-outfits-for-the-summer-season

12 Sweet Feminine Aesthetic Outfits for the Summer Season

March 13, 2026

Apple Watch Series 12 may relaunch a throwback feature, but no redesign

April 10, 2026
hansmaker-presents-the-d1-ultra:-a-dual-laser-engraver-designed-for-each-material-–-techenger

Hansmaker presents the D1 Ultra: a dual laser engraver designed for each material – Techenger

0
nascar-driver-denny-hamlin-breaks-silence-after-father-dies-in-house-fire

NASCAR driver Denny Hamlin breaks silence after father dies in house fire

0
fivio-foreign-checks-himself-into-a-$10,000-rehab-center-to-get-his-mind-straight

Fivio Foreign checks himself into a $10,000 rehab center to get his mind straight

0
david-beckham-leaves-brooklyn-for-his-2025-instagram-tribute-amid-family-feud

David Beckham leaves Brooklyn for his 2025 Instagram tribute amid family feud

0
what

What

May 11, 2026
a-fake-openai-repository-has-taken-the-top-spot-on-hugging-face-–-but-it’s-just-spreading-infostealer-malware

A fake OpenAI repository has taken the top spot on Hugging Face – but it’s just spreading infostealer malware

May 11, 2026

AI monitors your every move on the road. These state laws push back

May 11, 2026

Amazon is being sued over Fire TV sticks that stopped working. Here’s what you need to know

May 11, 2026

Recent News

what

What

May 11, 2026
a-fake-openai-repository-has-taken-the-top-spot-on-hugging-face-–-but-it’s-just-spreading-infostealer-malware

A fake OpenAI repository has taken the top spot on Hugging Face – but it’s just spreading infostealer malware

May 11, 2026

AI monitors your every move on the road. These state laws push back

May 11, 2026

Amazon is being sued over Fire TV sticks that stopped working. Here’s what you need to know

May 11, 2026
Vidianews

Trusted news coverage delivering accurate reporting, breaking headlines, and insightful analysis on global events, business, politics, and tech.

Follow Us

Browse by Category

  • Business
  • Entertainment
  • Faith
  • Gadget
  • Gaming
  • General
  • Health
  • Lifestyle
  • Movie
  • News
  • Politics
  • Review
  • Science
  • Sports
  • Startup
  • Tech
  • Travel
  • World

Recent News

what

What

May 11, 2026
a-fake-openai-repository-has-taken-the-top-spot-on-hugging-face-–-but-it’s-just-spreading-infostealer-malware

A fake OpenAI repository has taken the top spot on Hugging Face – but it’s just spreading infostealer malware

May 11, 2026
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© © Copyrights 2026 Vidianews. All Rights Reserved. Designed by Vidianews

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result

© © Copyrights 2026 Vidianews. All Rights Reserved. Designed by Vidianews

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?
Go to mobile version