Hugging Face OpenAI Filter Malware
Key point
A fake OpenAI Privacy Filter on Hugging Face reportedly distributed a Rust infostealer.
Details
A repository disguised as OpenAI Privacy Filter on Hugging Face reportedly recorded 244,000 downloads before being removed.
The actual file was not a PII-scrubbing tool but a Rust infostealer. It executed via a Windows path, established persistence, and weakened security defenses.
The theft targets are as follows.
- wallets
- browser data
- Discord tokens
- SSH keys
- FTP/VPN creds
This shows the supply chain risk that paths used to download AI models and utilities can also become entry points for malware.
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.