ChaosGPT pushed 71 files to two model repos on 16 Sep

On 21 September 2026 Antiy CERT published a report on a contamination attack against Chinese open-source model repositories. Antiy says an account named ChaosGPT uploaded the same 71 files to two official Hugging Face repositories. The account has since been deleted.

The first upload went to the Qwen organisation's Qwen3.8-27B repository as pull request #198. Hugging Face dates the commit 09bce50d at 10:01:48 GMT on 16 September, or 18:01 SGT.

The second upload went to DeepSeek's DeepSeek-V4.1-Flash repository 14 minutes later, at 10:15:53 GMT (18:15 SGT). Antiy calls it discussion #54. The Hugging Face API lists #54 as a pull request titled "Upload 71 files". Its commit is db668511.

Antiy says the files match byte for byte across both repositories. It rates the incident "Critical". Antiy's English page is an AI translation of its Chinese original.

Hugging Face page for Qwen3.8-27B pull request 198, Upload 71 files, opened by a deleted account Caption: Pull request 198 on the Qwen3.8-27B repository, as captured in Antiy's Chinese-language report (Figure 2-1) · Source: Antiy CERT, 21 Sep 2026 · link

Qwen, DeepSeek and teams that fetch pull-request refs

Alibaba's Qwen team and DeepSeek own the two repositories. Antiy says neither lab merged the uploads. Neither lab has published a statement on the incident.

Antiy puts the Qwen3.8-27B repository at more than 7.35 million downloads. It puts DeepSeek-V4.1-Flash at more than 480,000 downloads. On 28 September the Hugging Face API listed about 11 million all-time downloads for the Qwen repository and about 651,000 for the DeepSeek repository.

The risk sits with teams that fetch pull-request refs or open commits from these repositories. Mirrors, model caches and CI jobs that sync every ref can pick up the files. Antiy says the files would reach default clones only if a maintainer merged them.

An Italian attack agent called smart_chaos.py

The pull request diff for DeepSeek #54 adds 71 new files. Comments and names are in Italian. Antiy calls the project CyberWin, and its main agent calls itself CHAOS GPT.

The core file is smart_chaos.py, at 1,053 lines. Its main loop carries the comment "ESECUZIONE 100% AUTONOMA (NESSUN INPUT UTENTE)". Antiy translates that as "100% autonomous execution, no user input". Antiy says a local uncensored Llama model drives the loop.

Antiy lists what the agent can do once someone runs it:

  • Brute-force SSH logins with paramiko and scan ports.
  • Launch tools such as nmap, sqlmap and BeEF.
  • Control the mouse and keyboard, and read the screen.
  • Record from the webcam and microphone.
  • Run shell commands and write AI-generated payloads to disk.

The batch also holds five abliteration and filter-removal scripts that strip refusal behaviour from model weights. It holds 14 generatore scripts that build attack training datasets. The file chaos_web.py starts a Flask console on port 5000 on all interfaces. Antiy says the console has no authentication.

Antiy says nothing in the batch runs by itself. The files include no setup.py, no CI workflow and no install hook. Antiy found no change to model weights, tokenizers or training data. The scripts reference Llama models only.

Qwen's pull request is gone and both commits still load

We rechecked the Hugging Face API and web pages at 16:01 SGT on 28 September. They showed the same state as our earlier checks at 14:52 and 15:47 SGT:

  • Qwen pull request #198 returns "This pull request was deleted".
  • The Qwen commit 09bce50d still loads.
  • DeepSeek pull request #54 still shows status "open".
  • The DeepSeek commit db668511 still loads.

The attribution to a single amateur actor is Antiy's own analysis. Antiy bases it on hard-coded traces in the files, including a home directory name and an SSH public key. No other security firm has published a matching analysis. Neither lab has said who can reach the commits or when it will remove them.

Scan caches for the CyberWin file names this week

  1. Check mirrors, model caches and CI jobs that sync pull-request refs from these two repositories. Remove any copy of commits 09bce50d or db668511.
  2. Pin model downloads to a known commit on the main branch. Sync only the refs you need.
  3. Scan storage with the MD5 hashes and strings in Antiy's IoC tables. Strings include smart_chaos, CyberWin, blue-terinal and llama2-uncensored.
  4. Alert on model repositories that suddenly gain many files with no weights. Antiy recommends this check.
  5. If anyone ran smart_chaos.py or chaos_web.py, follow Antiy's cleanup steps. Kill the process tree, close ports 5000 and 11434, and review the hosts file and firewall rules.