A repository on Hugging Face, falsely claiming to be OpenAI's Privacy Filter model, became the top trending project, amassing approximately 244,000 downloads in less than 18 hours before it was taken down. According to NS3.AI, HiddenLayer reported that around 657 out of the 667 likes for the repository exhibited bot-like naming patterns. The malicious campaign deployed a multi-stage infostealer on Windows systems, which extracted browser passwords, Discord tokens, cryptocurrency wallet keys, and SSH credentials, subsequently transmitting them to servers controlled by the attackers.