World’s Largest AI Mannequin Repository Hugging Face Breached by Autonomous AI Agent


Ravie LakshmananJul 20, 2026AI Safety / Vulnerability

In an ironic twist, open-source synthetic intelligence (AI) platform Hugging Face revealed that it was the sufferer of a hack perpetrated by an autonomous AI agent system.

The corporate mentioned it detected and responded to the incident focusing on its manufacturing infrastructure earlier final week.

“We recognized unauthorized entry to a restricted set of inner datasets and to a number of credentials utilized by our providers,” the corporate said in an announcement.

Whereas an investigation into the intrusion stays ongoing, Hugging Face mentioned it has discovered no proof that the AI agent tampered with public, user-facing fashions, datasets, or Areas, and its personal software program provide chain.

The start line of the assault was the info processing pipeline itself, with a malicious dataset abusing two code execution paths, viz., in its distant code dataset loader and a template injection in a dataset configuration, to run code on a processing employee.

With that entry, the risk actor is alleged to have escalated to node-level entry, collected cloud and cluster credentials, and moved laterally into a number of inner clusters over a weekend.

The precise massive language mannequin (LLM) used to drag off the assault is unclear, however the marketing campaign was executed by an autonomous agent framework performing “many 1000’s of particular person actions throughout a swarm of short-lived sandboxes, with self-migrating command-and-control staged on public providers.”

Hugging Face mentioned it has since addressed the basis reason behind the difficulty, exactly the code execution pathways used for preliminary entry. It additionally carried out the next remediation steps –

  • Eliminated the attacker’s foothold throughout the affected clusters and rebuilt the compromised nodes
  • Revoked and rotated the affected credentials and tokens, and a broader rotation of secrets and techniques was undertaken as a precautionary measure.
  • Deployed extra guardrails and stricter admission controls on its clusters
  • Improved detection and alerting to make sure responders are notified inside minutes, 24×7

As an additional safeguard, Hugging Face is urging clients to rotate any entry tokens and assessment current exercise on their accounts.

The corporate additionally mentioned it turned to Z.ai’s GLM 5.2, a Chinese language open-weight mannequin, to conduct the forensic evaluation after Western frontier fashions refused requests containing actual assault instructions, exploit payloads, and command-and-control (C2) artifacts as a result of their security guardrails have been triggered and their incapacity to distinguish between an attacker and a reputable incident response effort.

“This expertise factors to a spot value planning for,” the New York-headquartered firm mentioned. “We have no idea which mannequin powered the attacker’s brokers, whether or not a jailbroken hosted mannequin or an unrestricted open-weight one; both means, the attacker was sure by no utilization coverage, whereas our personal forensic work was blocked by the guardrails of the hosted fashions we first tried.”

“The sensible lesson for defenders: have a succesful mannequin you’ll be able to run by yourself infrastructure vetted and prepared earlier than an incident, each to keep away from guardrail lockout and to maintain attacker knowledge and credentials from leaving your atmosphere.”