A fake AI model pretending to be an official OpenAI release was recently discovered on Hugging Face, one of the world’s largest AI model-sharing platforms.

According to cybersecurity researchers at HiddenLayer, the malicious repository was designed to look almost identical to OpenAI’s legitimate “Privacy Filter” project. Instead of providing a useful AI model, it secretly installed information-stealing malware on Windows computers.

Before being removed, the fake repository recorded approximately 244,000 downloads, although researchers believe the download count may have been artificially inflated to make the project appear more trustworthy.

How the Attack Worked

The malicious repository, named Open-OSS/privacy-filter, copied the appearance of OpenAI’s original project, including its documentation and setup instructions.

However, instead of installing an AI model, users were instructed to run files such as:

  • start.bat (Windows)
  • python loader.py (Linux and macOS)

The included loader.py script secretly downloaded and executed malware on Windows systems.

Researchers found that the malware disabled security checks before connecting to remote servers to download additional malicious files.

What Information Did the Malware Steal?

According to HiddenLayer, the malware focused on collecting sensitive user information.

It targeted:

  • Saved browser passwords
  • Browser cookies
  • Discord account data
  • Cryptocurrency wallets
  • FileZilla FTP credentials
  • System information
  • Browser sessions

The malware also attempted to bypass Windows security protections, making it more difficult to detect.

AI Model Repositories Becoming a Cybersecurity Risk

This incident highlights a growing concern in the AI industry.

Developers increasingly download AI models directly from public repositories like Hugging Face and integrate them into personal or business projects.

While AI models themselves may be safe, attackers are now hiding malicious code inside:

  • Installation scripts
  • Setup files
  • Python loaders
  • Dependency packages
  • Configuration files

Instead of attacking AI models directly, cybercriminals are targeting the software developers use alongside them.

More Fake AI Repositories Discovered

Researchers discovered that this wasn’t an isolated attack.

HiddenLayer identified six additional Hugging Face repositories using nearly identical malware delivery techniques.

The attackers reused the same infrastructure, suggesting a coordinated campaign aimed at developers working with artificial intelligence.

Hugging Face Removed the Repository

After the issue was reported, Hugging Face removed the malicious repository from its platform.

Security experts recommend that anyone who downloaded and executed files from the fake project should immediately:

  • Disconnect the affected device from the internet
  • Change passwords for important accounts
  • Revoke active login sessions
  • Scan the system for malware
  • Consider reinstalling Windows if compromise is confirmed

Since browser session cookies may have been stolen, changing passwords alone may not be enough.

Stay updated with the VitalStack.

Read More on VitalStack

Enjoyed this article?

Subscribe for weekly deep-dives on AI and health — straight to your inbox.