Fake OpenAI Repo Hit #1 on Hugging Face—And Stole Passwords While It Trended – Decrypt

May 13, 2026 - 01:15
Fake OpenAI Repo Hit #1 on Hugging Face—And Stole Passwords While It Trended – Decrypt
In brief A malicious Hugging Face repository impersonating OpenAI’s Privacy Filter model reached #1 trending on the platform. The malware registered approximately 244,000 downloads and 667 likes in under 18 hours before being removed. The repository delivered a six-stage infostealer that harvested browser passwords, Discord tokens, crypto wallet keys, and SSH credentials from Windows machines—then...

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Angry Angry 0
Sad Sad 0
Wow Wow 0