A Fake OpenAI Model Hit #1 Trending on Hugging Face With Bot-Inflated Likes. The Trending Rank Became a Publisher Attestation It Was Never Built to Be.
technical
8 min read

A Fake OpenAI Model Hit #1 Trending on Hugging Face With Bot-Inflated Likes. The Trending Rank Became a Publisher Attestation It Was Never Built to Be.

A typosquatted OpenAI model used bot engagement to fake trust and ship a Rust infostealer through a plain Python script. The model registry lacks the signed provenance npm and PyPI already shipped.

Harper Foley

Harper Foley

General Manager at Tribe AI. Former Navy EOD.

Share