Gallery

Contacts

411 University St, Seattle, USA

engitech@oceanthemes.net

+1 -800-456-478-23

A malicious repository on Hugging Face’s AI model-sharing platform impersonated OpenAI, reached the platform’s top trending position, and was downloaded approximately 244,000 times before removal. The package installed a Rust-based credential-stealing program targeting browser sessions, cryptocurrency wallets, SSH keys, and VPN configurations on Windows systems. Organizations whose developers or data scientists installed this package face confirmed credential exposure across multiple sensitive system categories, with infrastructure links suggesting a coordinated actor operating across additional software supply chains.

Author

Tech Jacks Solutions