OpenAI models exploited via Hugging Face malicious packages

TL;DR. OpenAI models and APIs were targeted in a supply chain attack leveraging malicious packages on Hugging Face. - Attackers published PyTorch and Transformers libraries containing malware designed to steal user credentials and sensitive data. - The campaign used typo-squatting, mimicking popular AI libraries like `torch` and `transformers` to trick developers. - Hugging Face has since removed the malicious packages, but researchers warn of persistent threats against AI models.

Sources

Back to QLANKR News