AI news story
Hugging Face hosted malicious software masquerading as OpenAI release
A malicious Hugging Face repository that posed as an OpenAI release delivered infostealer malware to Windows machines and recorded about 244,000 downloads before removal, according to research from AI security firm HiddenLayer. The number of download
Editor's take
A security firm uncovered a malicious repository on Hugging Face, disguised as an OpenAI model release, which infected approximately 244,000 Windows machines with infostealer malware before its removal.
This incident highlights the growing attack surface as AI development platforms become central hubs for model sharing and experimentation. The sheer volume of downloads indicates a broad reach and a significant number of users, likely developers and researchers, who are either unaware of or susceptible to such social engineering tactics. It underscores the urgent need for robust security vetting processes on platforms like Hugging Face, especially as they host increasingly complex and potentially executable AI code.
Future attention should focus on the effectiveness of Hugging Face's internal security protocols and whether similar incidents have gone undetected. Moreover, the long-term impact on user trust and the potential for more sophisticated supply chain attacks targeting AI ecosystems will be critical indicators of evolving threats.
Signal score: 5
This event was corroborated by 13 independent sources. The signal score weighs cross-source corroboration, recency, source weight and topic salience. How we rank stories.
Original reporting
This story summarises reporting published by AI News. Read the original article at AI News.