Particle.news
Download on the App Store

Hugging Face Breached by Autonomous AI Agent

Hugging Face says a malicious dataset exploited two code‑execution flaws to steal internal credentials, and forensic analysis was completed on a self‑hosted open‑weight model after hosted models blocked queries.

Overview

  • Hugging Face disclosed on July 16 that it detected and contained an intrusion into part of its production infrastructure that accessed a limited set of internal datasets and several service credentials.
  • The company says the attack began when a uploaded malicious dataset abused two dataset‑processing flaws—a remote‑code dataset loader and a template‑injection in a dataset configuration—to run code on a processing worker and escalate to node‑level access.
  • Investigators logged more than 17,000 attacker actions and say the campaign was executed end‑to‑end by an autonomous, agentic AI framework that ran thousands of short‑lived sandboxes and used public services for moving command‑and‑control.
  • Hugging Face reports it patched the exploited code paths, removed the attacker’s foothold, rebuilt affected nodes, revoked and rotated impacted credentials, deployed stricter admission controls, and engaged outside forensics and law enforcement.
  • So far the company says it has found no evidence of tampering with public models, datasets, Spaces, or its software supply chain and is urging users to rotate access tokens and review account activity while the investigation continues.