OpenAI models exploited via Hugging Face malicious packages
TL;DR. OpenAI models and APIs were targeted in a supply chain attack leveraging malicious packages on Hugging Face. - Attackers published PyTorch and Transformers libraries containing malware designed to steal user credentials and sensitive data. - The campaign used typo-squatting, mimicking popular AI libraries like `torch` and `transformers` to trick developers. - Hugging Face has since removed the malicious packages, but researchers warn of persistent threats against AI models.
- Malicious packages impersonating popular AI libraries (e.g., `torch`, `transformers`) were uploaded to Hugging Face.
- These packages contained malware designed to steal environment variables, Hugging Face tokens, AWS credentials, and other sensitive data.
- The attack specifically targeted OpenAI API keys and models, aiming to compromise AI development environments.
- Hugging Face swiftly removed the identified malicious content, but the incident highlights AI supply chain vulnerabilities.
- Researchers recommend validating package sources and implementing robust security practices for AI development.
Sources
- Open AI models hacked into HuggingFace — instagram.com
- gizmodo.com — gizmodo.com