logo
  • menu
  • Markets
  • ETFs
  • Live
  • Spot
  • Futures
  • Learn
  • Sign In
  • Sign Up
  • Downloads
  • English
  • |
  • USD
  • |
Sign Up
Crypto PricesLearnLatest NewsDownloadsMarketsSpotAnnouncements
Home/
Latest News/
Live

Fake OpenAI Repo Hit #1 on Hugging Face—And Stole Passwords While It Trended

By Decrypt
May 13, 2026
4.1 
★
★
★
★
★
★
★
★
★
★
 214 User Rating
Share

Within days, a fake account named "Open-OSS" published a near-identical repository called privacy-filter. The model card was copied word for word from OpenAI's. The only difference in the “readme” file: instructions to clone the repo and run a file called start.bat on Windows, or loader.py on Linux and Mac.

The download numbers were almost certainly inflated the same way. Manufactured social proof to make the bait look real.

How the malware actually worked

The malware basically worked like a poisoned pill wrapped in a very convincing candy coating. The loader.py script opens with fake model training output—progress bars, synthetic datasets, dummy class names—designed to look like a real AI loader is running.

Under the hood, it quietly disables security checks, pulls an encoded command from a public JSON paste site (a smart trick: no need to update the repository when the payload changes), and passes that command to PowerShell running completely hidden in the background. Windows users see nothing.

That command downloads a second script from a domain mimicking a blockchain analytics API. That script downloads the actual malware—a custom-built infostealer written in Rust—adds it to Windows Defender's exclusions list, then launches it at SYSTEM-level privileges via a scheduled task that immediately deletes itself after firing. The whole chain runs and cleans up after itself, leaving almost no trace.

The final payload is thorough. It grabs everything stored in Chrome and Firefox—saved passwords, session cookies, browser history, encryption keys, everything. It targets Discord accounts, cryptocurrency wallet seed phrases, SSH keys, FTP credentials, and takes screenshots across all monitors. Then it packages everything as a compressed JSON bundle and ships it to attacker-controlled servers.

There’s no need for us to tell you what the hackers can do with all that information later.

The malware also checks whether it's running in a virtual machine or a security sandbox, and quits quietly if it detects one. It's designed to run once on real targets, steal everything, and disappear.

Why this is bigger than just one repo

This isn't an isolated incident. It's part of a pattern. HiddenLayer identified six additional repositories under a separate Hugging Face account named "anthfu," uploaded in late April, using the exact same malicious loader pointing to the exact same command server. Those repos impersonated models like Qwen3, DeepSeek, and Bonsai to lure AI developers.

What if you downloaded it?

If you cloned Open-OSS/privacy-filter on a Windows machine and ran any file from it, you should treat the device as fully compromised. Don't log into anything from that machine before wiping it.

After that, change all the credentials that were stored in your browser—passwords, session cookies, OAuth tokens. Move any crypto funds to a new wallet generated on a clean device ASAP and assume seed phrases were stolen.

Since it also gets your Discord information, and that service is heavily automated, you should invalidate your Discord sessions and reset that password. Any SSH keys or FTP credentials on that machine should be considered burned.

The repository is now removed. Huggingface has not disclosed what, if any, additional screening measures it plans to implement for trending repositories.

As of now, seven confirmed malicious repositories from this campaign have been identified. How many more exist—or existed before being detected—remains unknown.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of BitKan. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. BitKan shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. Products mentioned in this article may not be available in your region.

Latest News

Industry

Cryptocurrency

Airdrop

Markets

  • Invesco Files for Tokenized Fund to Back Stablecoin Reserves

    Invesco Files for Tokenized Fund to Back Stablecoin Reserves

    Invesco has officially filed with the U.S. Securities and Exchange Commission (SEC) to launch the Invesco Stablecoin Reserves Onchain Fund, a new vehicle designed to offer stablecoin issuers a compliant way to manage their collateral.
    Martha Grizzard
    Jun 26, 2026
  • Spark and Uniswap Target $4T Market with New FX Infrastructure

    Spark and Uniswap Target $4T Market with New FX Infrastructure

    Uniswap and the decentralized finance protocol Spark have launched a shared liquidity infrastructure designed to function as a foreign-exchange network for the growing number of stablecoin issuers.
    Wayne Ingram
    Jun 26, 2026
  • Ethereum Foundation to Cut Budget by 40% in Major Restructuring

    Ethereum Foundation to Cut Budget by 40% in Major Restructuring

    The Ethereum Foundation (EF) has announced a comprehensive reorganization that includes a 40% reduction in its 2026 budget and a 20% cut to its workforce, signaling a shift toward a leaner, endowment-style operational model for the blockchain ecosystem.
    Wayne Ingram
    Jun 25, 2026
  • Japan Regulators Greenlight Ripple’s RLUSD Stablecoin Launch

    Japan Regulators Greenlight Ripple’s RLUSD Stablecoin Launch

    The Japan Financial Services Agency (JFSA) approved RLUSD under the Payment Services Act.
    Wayne Ingram
    Jun 25, 2026
  • SpaceX Prices Record $75B IPO at $135, Hits $1.8T Valuation

    SpaceX Prices Record $75B IPO at $135, Hits $1.8T Valuation

    SpaceX has officially executed the largest initial public offering in Wall Street history, substantially eclipsing all previous market records.
    Wayne Ingram
    Jun 12, 2026
View more data 
BTCBTC(BTC)
$0
--(Last 24h)
SpotFutures

Top

View more
  1. 1S&P 500 Reclaims 200-Day Moving Average, Bitcoin Gains
  2. 2Trump Softens His Stance on Reciprocal Tariffs, US Stocks and Crypto Markets Rise
  3. 3Vitalik Buterin : The current price of ETH has not been affected by the merger event
  4. 4Vibhu Norby : Solana Spaces store to bring 100K people to Solana per month
  5. 5CZ: compared with the record high nine months ago, the current situation of the industry is much better

Top Gainers

View more
Adventure Gold
Adventure GoldAGLD

$0.2489

+104.18%
Pundi X
Pundi XPUNDIX

$0.1175

+52.01%
Bella Protocol
Bella ProtocolBEL

$0.1940

+28.65%
Broccoli
BroccoliBROCCOLIF3B

$0.005279

+23.83%
Jotchua
JotchuaJOTCHUA

$0.0112

+22.55%

Top Trending

View more
Adventure Gold
Adventure GoldAGLD

$0.2479

+103.36%
LAB
LABLAB

$20.2993

+12.43%
SpaceX
SpaceXSPCXB

$153.990

+1.32%
Block Street
Block StreetBSB

$0.3119

+3.10%
AAVE
AAVEAAVE

$94.6800

+15.53%

Recently added

View more
Nesa
NesaNES

$0.1953

-3.84%
Arcium
ArciumARX

$0.2626

+4.46%
Ambire AdEx
Ambire AdExADX

$0.0567

+0.89%
Re
ReRE

$0.5504

-4.26%
o1 exchange
o1 exchangeO

$0.4064

-24.81%

Learn

View more
  1. 1Crypto Trading Bots: What Are They and How Do They Work?
  2. 2What Are Appchains? How Do Application-Specific Blockchains Work?
  3. 3What Is Chain Abstraction? What Are the Advantages and Challenges?
  4. 4What Are Intent-Based Transactions? How Do They Work?
  5. 5What Are Modular Blockchains? How Do They Scale Networks?
About Us
  • About BitKan
  • Contact Us
  • Announcements
  • VIP Program
  • BitKan Ambassador
  • Institutional Services
Products
  • Spot
  • Futures
  • Crypto Prices
  • Learn
  • News
  • Markets
  • How to Buy Crypto
  • BTC to USD Calculator
  • Reward
Help
  • Help Center
  • Email Us
  • Live Chat
  • Download APP
  • Listing Application
  • Buy Bitcoin
  • Buy Ethereum
  • Buy Dogecoin
  • Buy Altcoins
Terms
  • Terms of Use
  • Privacy Policy
  • Trading Rules
  • Fee
K-Site
English
About Us
+
  • About BitKan
  • Contact Us
  • Announcements
  • VIP Program
  • BitKan Ambassador
  • Institutional Services
Products
+
  • Spot
  • Futures
  • Crypto Prices
  • Learn
  • News
  • Markets
  • How to Buy Crypto
  • BTC to USD Calculator
  • Reward
Help
+
  • Help Center
  • Email Us
  • Live Chat
  • Download APP
  • Listing Application
  • Buy Bitcoin
  • Buy Ethereum
  • Buy Dogecoin
  • Buy Altcoins
Terms
+
  • Terms of Use
  • Privacy Policy
  • Trading Rules
  • Fee
K-Site
+
  • Twitter
  • Facebook
  • Telegram
  • YouTube
  • Instagram
  • Medium
  • Linkedin
@2012-2026 BITKAN.com