Machine LearningHow a Fake OpenAI Package Hijacked Hugging Face and Exposed ML Supply Chains
A malicious repository posing as an official OpenAI tool reached the top trending spot on Hugging Face, tricking thousands into downloading a hidden Rust infostealer. We break down the technical execution of the Open-OSS attack and what it means for the future of open-source machine learning security.







