Open-OSS/privacy-filter: Typosquatting the AI Model Registry
A Hugging Face repo typosquatted OpenAI's Privacy Filter, hit #1 trending on 244K downloads in 18 hours, then ran a Rust infostealer. The full attack chain.
3 articles with this tag.
A Hugging Face repo typosquatted OpenAI's Privacy Filter, hit #1 trending on 244K downloads in 18 hours, then ran a Rust infostealer. The full attack chain.
TeamPCP pushed a credential stealer into litellm 1.82.7 and 1.82.8 on PyPI via a compromised Trivy action. What it did, and why AI skills are next.
ClawHavoc was a January 2026 poisoning campaign on ClawHub: 1,184 malicious agent skills from 12 author IDs, most delivering the AMOS macOS stealer.