AI Devs Beware: Fake OpenAI Tool Becomes Hugging Face Top Trend to Spread Malware
A malicious repository impersonating OpenAI's 'Privacy Filter' managed to reach the number one spot on Hugging Face's trending list, resulting in over 244,000 downloads. The repository claimed to offer an open-weight model for data privacy but instead delivered a Rust-based information stealer targeting Windows users. This incident highlights a growing trend of supply chain attacks within the AI ecosystem, where attackers leverage the popularity of trusted brands to distribute malware via reputable machine learning platforms. Users who downloaded the repository may have had sensitive information, including credentials and system data, compromised by the malware.