- Open-source AI platform Hugging Face was hacked by an autonomous AI agent system that gained unauthorized access to internal datasets and credentials.
- The attack originated from a malicious dataset exploiting two code execution paths in the data processing pipeline, leading to lateral movement across several internal clusters.
- Hugging Face used Z.ai’s GLM 5.2 for forensic analysis after Western frontier models refused requests containing real attack commands due to safety guardrails.
In an ironic twist, Hugging Face revealed it was hacked by an autonomous AI agent system that penetrated its production infrastructure earlier last week. The company said it detected unauthorized access to a limited set of internal datasets and several service credentials, as stated in their incident report.
The attack began in the data processing pipeline, where a malicious dataset abused two code execution paths—a remote code dataset loader and a template injection in a dataset configuration—to run code on a processing worker. Consequently, the threat actor escalated to node-level access, collected cloud and cluster credentials, and moved laterally into several internal clusters over a weekend.
The exact large language model used remains unclear, but an autonomous agent framework executed the campaign, performing “many thousands of individual actions across a swarm of short-lived sandboxes, with self-migrating command-and-control staged on public services.” Hugging Face has since addressed the root cause, precisely the code execution pathways used for initial access.
Remediation included removing the attacker’s foothold across affected clusters, rebuilding compromised nodes, revoking and rotating affected credentials, and deploying additional guardrails and stricter admission controls. The company also turned to Z.ai’s GLM 5.2, a Chinese open-weight model, for forensic analysis after Western frontier models refused requests containing real attack commands and exploit payloads due to safety guardrails.
“We do not know which model powered the attacker’s agents, whether a jailbroken hosted model or an unrestricted open-weight one; either way, the attacker was bound by no usage policy, while our own forensic work was blocked by the guardrails of the hosted models we first tried.” Hugging Face urges customers to rotate any access tokens and review recent account activity as a further safeguard.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
