Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

A typosquatted repository on the Hugging Face AI platform impersonated an OpenAI tool and delivered credential-stealing malware to approximately 244,000 systems within 18 hours before removal. The payload, attributed with medium confidence to Silver Fox, a Chinese threat actor, targets browser-stored passwords, cryptocurrency wallets, Discord tokens, and FTP credentials on Windows systems. Organizations with AI/ML developers who download models from Hugging Face face direct credential compromise and potential downstream supply chain exposure.

Author

Tech Jacks Solutions