Just adding to your comment. Here's the blog post of the researchers who raised the issues: https://jfrog.com/blog/data-scientists-targeted-by-malicious-hugging-face-ml-models-with-silent-backdoor/
The problems appear to be malicious MLs in the hundreds, with different kinds of payloads, some of which the researchers were unsure if they did anything really malicious or not, because it could have been AI vulnerability researchers with sloppy practices.
The questions here are 1) did the OP ever download and run a truly malicious ML on his system, 2) if such information is absent (not sure, especially because the malicious MLs are not enumerated), were any confidential information extracted and would having run a malicious ML leave an undetectable silent backdoor as the article strongly suggests it may have.
If you believe in the article, then it seems one of the surest methods is to reinstall the OS, and resetting passwords on most important accounts.
Edited by Dill2046, 29 February 2024 - 08:53 PM.