AI news story

Hugging Face hosted malicious software masquerading as OpenAI release

A malicious Hugging Face repository that posed as an OpenAI release delivered infostealer malware to Windows machines and recorded about 244,000 downloads before removal, according to research from AI security firm HiddenLayer. The number of download

  • LLMs
  • Source: AI News
  • Published: 2026-05-12
  • Signal score: 5
  • 13 sources

Editor's take

A security firm uncovered a malicious repository on Hugging Face, disguised as an OpenAI model release, which infected approximately 244,000 Windows machines with infostealer malware before its removal.

This incident highlights the growing attack surface as AI development platforms become central hubs for model sharing and experimentation. The sheer volume of downloads indicates a broad reach and a significant number of users, likely developers and researchers, who are either unaware of or susceptible to such social engineering tactics. It underscores the urgent need for robust security vetting processes on platforms like Hugging Face, especially as they host increasingly complex and potentially executable AI code.

Future attention should focus on the effectiveness of Hugging Face's internal security protocols and whether similar incidents have gone undetected. Moreover, the long-term impact on user trust and the potential for more sophisticated supply chain attacks targeting AI ecosystems will be critical indicators of evolving threats.

Signal score: 5

This event was corroborated by 13 independent sources. The signal score weighs cross-source corroboration, recency, source weight and topic salience. How we rank stories.

More LLMs stories

  1. OpenAI acquires presentation startup NextSlide

    TechCrunch · 2026-08-08

    NextSlide says its team members are now working on ChatGPT.

  2. Claude Vs ChatGPT: How These AI Assistants Differ

    Engadget · 2026-08-08

    In a practical breakdown of how Claude and ChatGPT AI models differ, one tends to fall short when it comes to quality responses and overall user experience.

  3. Anthropic sets Claude Code to Auto Mode by default to protect developers from bad approvals

    The Decoder · 2026-08-08

    Starting August 14, Anthropic will make Auto Mode in Claude Code the default for Pro, Max, and Team plans. The company says it's safer.

  4. Responding to the next frontier of critical cyber capabilities

    OpenAI Blog · 2026-08-07

    OpenAI is sharing preliminary cybersecurity evaluations for Astra and the steps we’re taking to strengthen safeguards and security controls.

  5. OpenAI says it slowed Astra model development over security concerns

    TechCrunch · 2026-08-07

    OpenAI said this model, which is still in development, reached its "critical cybersecurity threshold," meaning it could independently identify and carry out cyberattacks against

  6. Presentation: Keeping ChatGPT Fast as AI Development Accelerates

    InfoQ · 2026-08-08

    Martin Spier explains how agentic workflows dramatically increase code change volume at OpenAI. He d