⚠️ Report: Black PR!!! Possible viruses inside! ⚠️

#2
by NodeLinker - opened

It is enough to analyze the people who liked this model to come to that conclusion. They all resemble each other in many ways...

Currently, the docker and ollama folders contain actual .exe files, not viruses.

However, the versions in docker and ollama there are old. Quite old, indeed. (Latest Docker version for Windows: 4.73.0 dated 2026-05-11; in this repository the version is 4.56.0 dated 2026-01-12. Latest Ollama version for Windows: v0.23.2 released 5 days ago; in this same repository it's v0.12.10 dated Nov 6, 2025.)

In the .gguf chat templates, there seems to be nothing dangerous, but I haven't looked more thoroughly than that.

The instructions on the website http://www.leanly-ai.top/ seem fine, nothing suspicious there -- but I only skimmed through them quickly and only in English. (By the way, they ask you to upload .exe files via Hugging Face.)

The model seems not to be a virus, but promoting it this way -- as if through auto‑registered accounts -- is just terrible.

Consider this discussion as a warning before you start. Previously on Hugging Face, there was a model that took first place in the trending section, and it also had artificially inflated likes and downloads -- the problem might run deeper. I would not use this model for these reasons. The rest is up to you.

Additionally, I’ll mention the .top domain, which was registered just barely a month ago. The problem with the .top domain is that it is very cheap to register, so using it for malicious purposes is easier.

And just because there are official .exe files sitting here today doesn’t mean they won’t be replaced with malicious ones five minutes later.

NodeLinker changed discussion title from Report: Black PR. to Report: Black PR!!!
NodeLinker changed discussion title from Report: Black PR!!! to ⚠️ Report: Black PR!!! Possible viruses inside! ⚠️

Sign up or log in to comment