Hugging face says autonomous AI agent breached its infrastructure

Hugging Face confirmed an autonomous AI agent breached its infrastructure through a malicious dataset in the company's data processing pipeline.

CSBadmin
2 Min Read

Hugging Face, the widely used platform for sharing open-source machine learning models, disclosed that an autonomous AI agent breached part of its production infrastructure last week. The intrusion was detected and contained, with the company finding unauthorized access to a limited set of internal datasets and service credentials.

The attack originated from a malicious dataset that exploited two code execution paths in the company’s dataset processing pipeline. A remote-code dataset loader and a template injection in a dataset configuration allowed the attacker to run code on a processing worker. From there, the actor escalated to node-level access, harvested cloud and cluster credentials, and moved laterally across several internal clusters over a weekend.

Hugging Face said the campaign was executed by an autonomous AI agent framework that used thousands of individual actions across short-lived sandboxes, with self-migrating command-and-control staged on public services. The company has found no evidence of tampering with public user-facing models, datasets, or software supply chain integrity.

In response, Hugging Face blocked the exploited code execution paths, rebuilt compromised nodes, rotated credentials, and implemented stricter cluster admission controls. The company urged users to rotate access tokens and review account activity as a precautionary measure.

During the investigation, the company used LLM-powered analysis agents to reconstruct the attack timeline from over 17,000 recorded events. Notably, commercial AI models blocked some forensic analysis due to safety guardrails flagging real attack data, forcing the team to use an open-weight model on its own infrastructure instead.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.