"The campaign was run by an autonomous agent framework (appearing to be built on an agentic security-research harness - used LLM still not known) executing many thousands of individual actions across a swarm of short-lived sandboxes, with self-migrating command-and-control staged on public services," Hugging Face disclosed.
How the intrusion began in a data-processing pipeline
Hugging Face says the attackers initiated the intrusion by uploading a malicious dataset into the company's data-processing pipeline. That dataset exploited two code-execution vulnerabilities — described by the company as a template injection in a dataset configuration and a remote-code dataset loader — to run code on a processing worker. Once code execution was achieved on that worker, the intruders were able to steal cloud and cluster credentials and move laterally across several internal clusters.
Agentic attacker mechanics observed by Hugging Face
The company characterized the intrusion as an "autonomous agent framework" campaign that carried out "many thousands of individual actions" across a swarm of short-lived sandboxes. According to Hugging Face, the attacker staged self-migrating command-and-control on public services. The firm also said the framework "appearing to be built on an agentic security-research harness" and added that the specific LLM used is "still not known."
Hugging Face noted a defensive complication: initial forensic work was impeded by the guardrails of hosted models the company first tried, which the company contrasted with the attacker's agents that were "bound by no usage policy." The company drew a practical lesson: "have a capable model you can run on your own infrastructure vetted and ready before an incident, both to avoid guardrail lockout and to keep attacker data and credentials from leaving your environment."
Containment steps: evictions, rebuilds, and credential rotation
In response to the intrusion, Hugging Face says it closed the vulnerable code-execution paths, evicted the attacker, rebuilt the compromised nodes, and revoked and rotated all affected credentials. The two specific execution paths cited were the template-injection vector in dataset configuration and the remote-code dataset loader.
The company also reported deploying improved malicious-activity detection systems, has reported the incident to law enforcement, and is working with external forensic experts to assess impact.
Scope and outstanding investigations
Hugging Face said it has found no evidence to date of tampering with public-facing models, public datasets, or Spaces, and that its software supply chain has been "verified clean." The company is nevertheless still investigating whether partner or customer data was affected and pledged to contact any affected parties directly.
Hugging Face acknowledged it does not yet know which model powered the attacker's agents — whether a "jailbroken hosted model or an unrestricted open-weight one" — and emphasized that either way the attacker operated without usage-policy constraints.
What this means for security teams, partners, and users
- Security teams and technologists: The incident highlights an attack path tied to dataset handling and dataset-loader functionality; defenders should prioritize controls around dataset ingestion, template handling, and remote-code loaders, and consider the company's explicit recommendation to have an internally run, vetted model available for incident response.
- Partners and customers: Hugging Face is investigating potential exposure and will contact affected parties directly. The company has advised users to rotate access tokens and to review recent account activity for signs of suspicious behavior.
- Platform operators and open-source maintainers: The disclosure underscores the risk of malicious content uploaded to collaborative model and dataset platforms — Hugging Face noted that threat actors have abused the platform in recent years to push malicious AI/ML models and infostealer malware and to spread thousands of Android malware variants.
This breach is notable both for its use of an autonomous, agentic framework and for the attack vector: malicious dataset content that triggers code execution in data-processing infrastructure. Hugging Face has taken immediate technical and investigative steps, but the company still does not know which model family powered the attacking agents and is continuing its analysis. For organizations that host or consume models and datasets, the disclosure underlines two practical actions cited by Hugging Face: rotate credentials and ensure you can run a capable model on your own infrastructure to avoid forensic blind spots imposed by hosted-model guardrails.
Original reporting: https://www.bleepingcomputer.com/news/security/hugging-face-breach-autonomous-ai-agent-system-internal-datasets-credentials/




