A malicious Hugging Face repository named Open-OSS/privacy-filter impersonated an OpenAI release and delivered a Rust-based infostealer to Windows systems, accumulating 244,000 downloads and reaching #1 trending on the platform within 18 hours before removal. The loader.py script used decoy AI model code to conceal an infection chain that disabled SSL verification, used jsonkeeper.com as a C2 channel, established persistence via a fake Microsoft Edge scheduled task, and targeted browser credentials, crypto wallets, Discord, and FileZilla. HiddenLayer linked the campaign to six additional repositories and earlier npm/PyPI supply chain attacks. Security analysts warn that traditional SCA tools are ill-equipped to detect malicious logic in AI artifacts, and recommend enterprises establish dedicated governance controls at the AI registry layer, treat affected systems as fully compromised, rotate credentials, and invalidate active sessions.