2 min read

Hugging Face says AI agent breached internal systems

Hugging Face says attackers used an autonomous AI agent system to breach production infrastructure and steal internal datasets and credentials.

Image: BleepingComputer

Hugging Face says attackers breached its production infrastructure using an autonomous AI agent system, gaining access to internal datasets and credentials after exploiting vulnerabilities in its data-processing pipeline.

The company, which hosts more than 45,000 models and is used by over 50,000 organizations, said it is still investigating whether partner or customer data was affected. It said any impacted parties will be contacted directly. So far, Hugging Face says it has found no evidence of tampering with public-facing models, datasets, or Spaces, and that its software supply chain has been “verified clean.”

According to an incident disclosure published Thursday, the attack started with a malicious dataset that exploited two code-execution vulnerabilities on a processing worker. Hugging Face said those flaws were a template injection in a dataset configuration and a remote code dataset loader. The attackers then stole cloud and cluster credentials and moved laterally across multiple internal clusters.

“The campaign was run by an autonomous agent framework (appearing to be built on an agentic security-research harness — used LLM still not known) executing many thousands of individual actions across a swarm of short-lived sandboxes, with self-migrating command-and-control staged on public services.” “This matches the 'agentic attacker' scenario the industry has been forecasting.”

Hugging Face

In response, the company says it has:

Recommended reading

WordPress bugs are now under attack at scale

  • closed the vulnerable code-execution paths
  • evicted the attacker
  • rebuilt compromised nodes
  • revoked and rotated affected credentials
  • deployed improved malicious activity detection
  • reported the incident to law enforcement
  • brought in external forensic experts

Hugging Face said it does not know which model powered the attack, whether it was a jailbroken hosted model or an unrestricted open-weight model. It also said its own forensic work was initially hindered by the guardrails on hosted models it tried to use.

“The practical lesson for defenders: have a capable model you can run on your own infrastructure vetted and ready before an incident, both to avoid guardrail lockout and to keep attacker data and credentials from leaving your environment.”

Hugging Face

The company advised users to rotate access tokens and review recent account activity for suspicious behavior. It added that while this is the first disclosed platform security incident tied to an AI agent, it is not Hugging Face’s first breach. Two years ago, the company revoked some members' authentication secrets after attackers breached its Spaces platform. In recent years, threat actors have also used the service to distribute malicious AI/ML models, infostealer malware, and thousands of Android malware variants.

Sophia Reynolds

Security Editor

Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.

via BleepingComputer

// Keep reading