Attackers typosquatted an OpenAI repo on HuggingFace, distributing an infostealer disguised as a “privacy filter” model The malware disabled SSL checks, escalated privileges, and deployed the sefirah ...