Malicious Hugging Face model masquerading as OpenAI release
A malicious Hugging Face repository posing as an OpenAI release delivered infostealer malware to Windows systems and logged 244,000 downloads before being removed, raising fresh concerns about how enterprises source and
Original Disclosure
https://www.csoonline.com/article/4169407/malicious-hugging…
Severity
medium
Sector
tech
Disclosure date
May 11, 2026
Indexed
10 hours, 6 minutes ago