Attackers can create malicious repositories on platforms like Hugging Face by typo-squatting legitimate project names and embedding malware in seemingly legitimate code, as demonstrated by a malicious 'privacyfilter' repository that impersonated OpenAI's project and delivered information-stealing malware to Windows users before being removed.
深度探索
先修知识
- 暂无数据。
后续步骤
- 暂无数据。
深度探索
Hugging Face Repo Malware: OpenAI Copycat Clone本站添加:
Malicious hugging face repository that reached the platform's trending list and impersonated OpenAI's privacy filter project to deliver information-stealing malware to Windows users. The repository briefly reached number one on hugging face and accumulated nearly a quarter of a million downloads before the platform responded to reports and removed it. Researchers at Hidden Layer Oh, come on.
A company focused on safeguarding AI and ML models against attacks discovered the campaign on May 7th. So, that's just a couple days ago. After noticing the malicious repository named open oss/privacyfilter.
The repository had typo-squatted OpenAI's legitimate privacy filter release, copied its model card nearly verbatim, and shipped a loader.py file that fetches and executes info-stealer malware on Windows machines.
So, going back to the copycat clones, right? Is that it's something that looks and feels almost identical to like a real thing, except there are small pieces of it that are malware. And in this case, it sounds like they did a pretty good job. This typo-squatting thing, if I understand correctly, is basically leveraging fact that there could be a a minor mis-type.
Like I was saying before, you see a Claude code ad, and it looks exactly like Anthropic and all this stuff, and but really it's not coming from Anthropic, it comes from Anthropia.
Like that's an example of like these typo-squatters is they're making really minor change, but it's almost invisible.
And so, unless you look at it really closely, you might miss it.
相关推荐
OpenHuman VS Hermes AI: Who Wins?
JulianGoldieSEO
285 views•2026-05-29
BREAKING: Microsoft’s New Image Generating Model Beat Out GPT 1.5 and Nano Banana 2
aimmediahouse
122 views•2026-06-03
Long-Running Agents — Build an Agent That Never Forgets with Google ADK
suryakunju
142 views•2026-05-30
I Made the Same Anime Fight Scene in Every AI Video Generator
NobleGooseAnime
295 views•2026-05-30
Nvidia Bets Big On AI PCs | New Chip To Power Windows Laptops | Technology | AI Updates | N18S
cnnnews18
3K views•2026-06-01
I Tested NEW Opus 4.8 on Four Projects (Updated LLM Leaderboard)
AICodingDaily
298 views•2026-05-29
3D Platformer Update - NO CAPES
SolarLune
294 views•2026-05-30
AI Doesn't Create Bias — It Inherits It
UXEvolved
176 views•2026-06-01











