Gallery

Contacts

411 University St, Seattle, USA

engitech@oceanthemes.net

+1 -800-456-478-23

A typosquatted repository on the Hugging Face AI platform impersonated an OpenAI tool and delivered credential-stealing malware to approximately 244,000 systems within 18 hours before removal. The payload, attributed with medium confidence to Silver Fox, a Chinese threat actor, targets browser-stored passwords, cryptocurrency wallets, Discord tokens, and FTP credentials on Windows systems. Organizations with AI/ML developers who download models from Hugging Face face direct credential compromise and potential downstream supply chain exposure.

Author

Tech Jacks Solutions