A malicious Hugging Face repository reached the platform’s trending list by impersonating OpenAI’s Privacy Filter open-weight model to distribute a Rust-based information stealer targeting Windows users. The project, named Open-OSS/privacy-filter, mimicked the legitimate version released by OpenAI last month (openai/privacy-filter), copying the entire repository structure.
