Fake OpenAI Privacy Filter Repo Hits #1 on Hugging Face, Draws 244K Downloads - The Hacker News
244K downloads. A fake OpenAI repo on Hugging Face just exposed the open model supply chain's critical vulnerability.

Why it matters
A malicious repository masquerading as an official OpenAI privacy filter achieved top ranking on Hugging Face and distributed infostealer malware to developers. This incident reveals systemic security gaps in open-source AI distribution channels—a governance and trust problem that will reshape how enterprises vet AI dependencies.
The key facts
6 to knowFake repository ranked #1 on Hugging Face
244K downloads before detection
Infostealer malware targeting developers and AI tools
Supply chain attack via open model distribution platform
Exposes blind spot in open model ecosystem governance
Published May 2026
Go to the source
Reuters Technologynews.google.com
Publisher excerpt: Fake OpenAI Privacy Filter Repo Hits #1 on Hugging Face, Draws 244K Downloads The Hacker News Supply Chain Attack: Fake OpenAI Repository on Hugging Face Distributes Infostealer Malware Targeting Developers and AI Tools Rescana Fake OpenAI Hugging Face OpenAI Repo Pushed Infostealer Malware…
