Fake OpenAI Privacy Filter Repo Delivers Windows Infostealer on Hugging Face

1 min read
Source: The Hacker News
Fake OpenAI Privacy Filter Repo Delivers Windows Infostealer on Hugging Face
Photo: The Hacker News
TL;DR Summary

A clone of OpenAI's Privacy Filter on Hugging Face impersonated the legitimate model to distribute a Windows infostealer via a loader that downloads payloads through Base64, JSON Keeper, and PowerShell, then sets up a one-shot scheduled task to run the final malware and exfiltrate data (screenshots, crypto wallets, browser data) to a remote domain while attempting to evade detection by disabling AMSI/ETW; the repo peaked at #1 with about 244,000 downloads before being disabled, and researchers link it to similar loaders and ValleyRAT-related campaigns targeting open-source ecosystems.

Share this article

Reading Insights

Total Reads

0

Unique Readers

8

Time Saved

3 min

vs 4 min read

Condensed

88%

73487 words

Want the full story? Read the original article

Read on The Hacker News