<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[伪装 OpenAI 隐私过滤模型的恶意仓库登顶 Hugging Face，下载量达 24.4 万次]]></title><description><![CDATA[<p dir="auto">安全研究机构 HiddenLayer 披露，一个名为"Open-OSS/privacy-filter"的恶意 Hugging Face 仓库完整复制了 OpenAI 于 2026 年 4 月发布的隐私过滤模型（Privacy Filter）的介绍文本，以此冒充官方仓库诱骗开发者下载。在被平台下架前，该仓库在约 18 小时内攀升至 Hugging Face 趋势榜第一位，下载量约 24.4 万次、获得 667 个点赞——研究人员认为上述数字系人为刷高，以制造可信度假象。OpenAI Privacy Filter 本是一款用于检测和脱敏非结构化文本中个人身份信息（PII）的开权重模型。</p>
<p dir="auto">攻击链分为多个阶段：用户克隆仓库后运行批处理脚本（Windows）或 Python 脚本，后者通过 JSON Keeper 公共粘贴服务作为"死投"中转解析器获取 PowerShell 指令，从远程服务器拉取多阶段下载器，最终部署一款基于 Rust 的信息窃取木马——可截图并抓取 Discord 账户、加密货币钱包及浏览器插件、系统元数据、FileZilla 配置、助记词等，经由 JSON 格式回传攻击者服务器，且全程不建立持久化驻留。HiddenLayer 另发现 6 个同类恶意仓库（均位于"anthfu"账号下），其基础设施与此前被归因于中国黑客组织"Silver Fox"的远控木马 ValleyRAT（Winos 4.0）存在关联，研究人员认为此次事件或属针对开源生态的更大规模供应链攻击。</p>
<p dir="auto"><a href="https://thehackernews.com/2026/05/fake-openai-privacy-filter-repo-hits-1.html" target="_blank" rel="noopener noreferrer nofollow ugc">The Hacker News</a> | <a href="https://www.hiddenlayer.com/research/malware-found-in-trending-hugging-face-repository-open-oss-privacy-filter" target="_blank" rel="noopener noreferrer nofollow ugc">HiddenLayer</a></p>
<p dir="auto"></p><div class="card col-md-9 col-lg-6 position-relative link-preview p-0">



<a href="https://thehackernews.com/2026/05/fake-openai-privacy-filter-repo-hits-1.html" title="Fake OpenAI Privacy Filter Repo Hits #1 on Hugging Face, Draws 244K Downloads">
<img src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiPtLFShq_XoM9Nzsl5kmSsF2UGsm6VhRoLNodcqRCdq45zqy4ekFVtamokNzEFifQknD502Wc0uFTBUdvLsBsYn4QAeVHSWLmhF2ROBMXutev8T6JjCGrrarzLhkSTUHLBq-nEWrF0WTb2epkX_3Ba5a6Gv_21R7PPQ_zCjhk7OU702Y10tJkcJiYG52D4/s1600/hugging-face-malware.jpg" class="card-img-top not-responsive" style="max-height:15rem" alt="Link Preview Image" />
</a>



<div class="card-body">
<h5 class="card-title">
<a class="text-decoration-none" href="https://thehackernews.com/2026/05/fake-openai-privacy-filter-repo-hits-1.html">
Fake OpenAI Privacy Filter Repo Hits #1 on Hugging Face, Draws 244K Downloads
</a>
</h5>
<p class="card-text line-clamp-3">Fake OpenAI Privacy Filter hit #1 on Hugging Face with 244,000 downloads, spreading infostealer malware to Windows users.</p>
</div>
<a href="https://thehackernews.com/2026/05/fake-openai-privacy-filter-repo-hits-1.html" class="card-footer text-body-secondary small d-flex gap-2 align-items-center lh-2">



<img src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgQQyjwPYjJP0wddSEB8Dlpr3dlnQUs52-WmlrZfqJoBPeOvv2Zoqlq-FhEAz_Xeprj_mtrI1MGCW1JS840JUjVEK6VoNe6zCNNTw_7YmyvNmf3E5pprZ3zqP8lszq74Wt97SvbJo5yeuyep0U6-nGs0vdarg4_WUrc5r6L0ML0xE-BsPipJd2-1PMHTvO1/s32-e365/thn.jpg" alt="favicon" class="not-responsive overflow-hiddden" style="max-width:21px;max-height:21px" />

















<p class="d-inline-block text-truncate mb-0">The Hacker News <span class="text-secondary">(thehackernews.com)</span></p>
</a>
</div><p></p>
]]></description><link>https://welinux.com//topic/301/伪装-openai-隐私过滤模型的恶意仓库登顶-hugging-face-下载量达-24.4-万次</link><generator>RSS for Node</generator><lastBuildDate>Mon, 18 May 2026 20:30:44 GMT</lastBuildDate><atom:link href="https://welinux.com//topic/301.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 11 May 2026 16:59:37 GMT</pubDate><ttl>60</ttl></channel></rss>