Hugging Face, one of the world’s largest open source artificial intelligence platforms, has disclosed that it was targeted in a cyberattack carried out by an autonomous AI agent system. According to the company, the incident affected its production infrastructure and was detected and contained earlier last week. During the investigation, Hugging Face identified unauthorized access to a limited set of internal datasets as well as several credentials used by its services. The company stated that the investigation is still ongoing, but so far it has found no evidence that the attackers modified public user facing models, datasets, Spaces, or its software supply chain.
According to the company, the attack originated through its data processing pipeline. Researchers determined that a malicious dataset exploited two separate code execution paths involving the remote code dataset loader and a template injection vulnerability within a dataset configuration. These weaknesses allowed the autonomous AI agent to execute code on a processing worker before escalating privileges to gain node level access. From there, the attacker collected cloud and cluster credentials and moved laterally into multiple internal clusters over the course of a weekend. Hugging Face noted that the exact large language model used by the attackers has not been identified. However, the company stated that the campaign relied on an autonomous agent framework capable of carrying out thousands of individual actions across numerous short lived sandbox environments while maintaining self migrating command and control infrastructure hosted on public services.
Following the discovery of the intrusion, Hugging Face implemented several remediation measures to secure its environment. The company addressed the code execution paths that enabled the initial compromise, removed the attacker’s access from affected clusters, rebuilt compromised nodes, and revoked and rotated impacted credentials and tokens. As an additional precaution, a broader rotation of secrets was also completed. The company strengthened security by deploying stricter admission controls across its clusters, introducing additional guardrails, and improving monitoring and alerting capabilities to enable around the clock detection and faster incident response. Hugging Face has also advised customers to rotate their access tokens and review recent account activity to ensure no unauthorized access has occurred.
During the forensic investigation, Hugging Face revealed that it used Z.ai’s GLM 5.2 open weight model after several hosted frontier AI models declined to process attack commands, exploit payloads, and command and control artifacts because their built in safety controls blocked the requests. The company stated that this created challenges for legitimate incident response efforts because the models could not distinguish between malicious activity and defensive security analysis. Hugging Face said the experience highlighted the importance of maintaining a capable AI model that can operate within an organization’s own infrastructure during security investigations. According to the company, defenders should ensure they have trusted models available for incident response to avoid safety related restrictions and prevent sensitive attacker data and credentials from leaving their environments during forensic analysis.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.