A malicious typosquatting repository on Hugging Face delivered infostealer malware targeting OpenAI-related projects, according to security reports [1, 2].
This breach underscores a critical vulnerability in the AI supply chain. As developers increasingly rely on third-party hubs to share models, the risk of compromised code entering production environments grows, potentially exposing sensitive corporate data, and intellectual property.
Researchers from HiddenLayer identified the threat on the Hugging Face model hub [2]. The attackers used typosquatting—a technique where a repository name closely mimics a legitimate one—to trick developers into downloading malicious software [2]. Once installed, the infostealer malware targeted projects associated with OpenAI [1, 2].
Hayete Gallot, the executive vice president of Microsoft Security, discussed the incident in an interview with Bloomberg Television [1]. Gallot said the event serves as a wake-up call for the entire industry [1]. The incident demonstrates how attackers are shifting their focus toward the infrastructure supporting artificial intelligence to find new points of entry.
The use of the Hugging Face hub for this attack highlights the trust developers place in open-source AI repositories. Because these platforms facilitate rapid deployment, security checks may be bypassed in favor of speed, a gap that malicious actors are now actively exploiting [2].
Microsoft and other security firms continue to monitor these distribution channels. The focus remains on creating more robust verification methods for AI models to ensure that the code being integrated into software is authentic, and untampered [1].
“The event serves as a wake-up call for the entire industry.”
The targeting of OpenAI-related projects via a trusted hub like Hugging Face signals a shift in the threat landscape. It suggests that the 'AI supply chain' is now a primary target for industrial espionage and data theft, meaning organizations can no longer assume that popular open-source AI repositories are inherently safe without rigorous auditing.


