Hugging Face hosted malicious software masquerading as OpenAI release
244,000 downloads. A fake OpenAI model on Hugging Face delivered infostealer malware before removal—exposing a critical supply-chain vulnerability in the AI ecosystem.

Why it matters
As AI model distribution becomes critical infrastructure, attackers are exploiting trust in platforms like Hugging Face. This incident highlights governance gaps in open-source AI repos and raises questions about verification, provenance, and platform security—issues every AI leader deploying community models needs to address.
The key facts
6 to know244,000 downloads of malicious repository before removal
Malware type: infostealer targeting Windows machines
Platform compromised: Hugging Face
Discovery source: HiddenLayer (AI security firm)
Attack vector: Repository masquerading as official OpenAI release
Download inflation: Attackers may have artificially inflated popularity metrics
Go to the source
AI Newsartificialintelligence-news.com
Publisher excerpt: A malicious Hugging Face repository that posed as an OpenAI release delivered infostealer malware to Windows machines and recorded about 244,000 downloads before removal, according to research from AI security firm HiddenLayer. The number of downloads may have been artificially inflated by the…