BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Fake OpenAI Model on Hugging Face Spreads Malware

Hugging Face repo impersonated OpenAI to deploy a sophisticated info-stealing malware campaign.

  • A trending malicious repository on Hugging Face impersonated OpenAI‘s Privacy Filter model to deploy a sophisticated information stealer.
  • The stealer harvested data from Discord, cryptocurrency wallets, and browsers, using a multi-stage PowerShell downloader to evade detection.
  • Attackers used a public JSON paste service to dynamically switch payloads, and the campaign shared infrastructure with earlier ValleyRAT attacks.
  • Researchers identified six additional malicious repositories with similar loader scripts, indicating a broader supply chain operation.

A malicious repository on the open-source platform Hugging Face impersonated a legitimate OpenAI model last week, delivering a dangerous information stealer to Windows users. This fake project, named Open-OSS/privacy-filter, copied the description from the real openai/privacy-filter to appear authentic. Consequently, it reached the #1 trending spot with approximately 244,000 downloads before being disabled.

- Advertisement -

The repository contained a Python loader script that fetched and executed malware, as detailed in a report from the HiddenLayer Research Team. Once run, the script disabled SSL verification and decoded a Base64-encoded URL from a JSON Keeper service to download a PowerShell command. This flexible use of a public paste service allowed attackers to switch payloads without altering the repository.

Subsequently, a batch script was downloaded to prepare the environment by elevating privileges and configuring Microsoft Defender exclusions. The final payload was a Rust-based stealer designed to capture screenshots and harvest sensitive data. “Despite using a scheduled task, this stage establishes no persistence: the task is destroyed before any reboot,” HiddenLayer explained.

The malware specifically targeted cryptocurrency wallets and extensions, Discord data, and browser information. It also performed checks for virtual machines and attempted to disable Windows security features like AMSI and ETW. Meanwhile, the stolen data was exfiltrated in JSON format to the “recargapopular[.]com” domain.

Further analysis revealed six more repositories, all under the “anthfu” user, using a similar Python loader to deploy the same stealer. The same domain, “api[.]eth-fastscan[.]org,” was also used to serve a different Windows executable. This executable beacons to a command-and-control server previously linked to a campaign delivering ValleyRAT via a malicious npm package, according to noted analysis last month.

- Advertisement -

Consequently, this attack represents a new initial access vector for ValleyRAT, a trojan typically spread through phishing and SEO poisoning. “The shared infrastructure suggests these campaigns are possibly linked and likely part of a broader supply chain operation targeting open-source ecosystems,” HiddenLayer said. The group exclusively using this malware is a Chinese hacking group known as Silver Fox.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Crypto Inflows Hit $4.9B Over 6 Weeks as BTC Topped $80K

Crypto investment products have seen six consecutive weeks of inflows, the longest streak since...

SUI Jumps 19% on Confidential Transactions Announcement

Sui (SUI) surged over 19% today, leading 24-hour cryptocurrency price gains.The rally follows an...

Strategy to Resume Bitcoin Purchases Amid Dividend Plans

Strategy signaled it will resume its Bitcoin purchases this week, having paused them ahead...

Firms roll out quantum-proof wallets ahead of blockchain upgrades

Cryptocurrency firms are deploying quantum-resistant wallets ahead of core blockchain protocol upgrades, fearing "Q-Day"...

Must Read

How Much Money Do You Need To Start In Crypto?

TL;DR -If you are wondering How Much Money Do You Need To Start In Crypto, note that is less than you are probably thinking....
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading