Hugging Face impersonation malware
·2026.05.08 01:20
Key point
Hugging Face's `Open-OSS/privacy-filter` has been reported as malware targeting Windows.
Details
Open-OSS/privacy-filter has been identified as a Windows infostealer impersonating an OpenAI privacy filter.
The disclosed flow is as follows.
- The Python dropper
loader.pydownloads a malicious PowerShell command from the internet - PowerShell then calls another PowerShell
- It downloads a suspicious EXE and runs it via Task Scheduler
The author included a tria.ge behavioral analysis link and stated that they reported the dropper and EXE to Microsoft and Hugging Face. They noted that Linux users are not affected.
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.