Breach404
Back to Insights
Data Security2 min readMay 9, 2026

Fake OpenAI repository on Hugging Face pushes infostealer malware

Attackers created a fake OpenAI repository on Hugging Face that impersonated a legitimate "Privacy Filter" project and distributed information-stealing malware to Windows users, even reaching the platform's trending list. Your organization should verify t

Could your website be vulnerable to attacks like this?

Run a free 10-point security scan on your site — headers, SSL, DNS, and more. Results in 15 seconds.

Test Your Site Now — It's Free