256 Newsroom — Uganda's Digital News Infrastructure
Business

World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent - The Hacker News

Share
World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent - The Hacker News
Image · Internet

What the report says

The Hacker News reported that Hugging Face, the New York-based open-source AI platform and model repository, disclosed a breach of its production infrastructure involving an autonomous AI agent system. According to the report, the company detected and responded to the incident earlier in the previous week and said the intruder reached a limited amount of internal dataset material and several service credentials.

The reported entry point was Hugging Face’s data-processing pipeline. A malicious dataset allegedly exploited two ways to execute code: a remote-code dataset loader and a template injection issue in a dataset configuration. From there, the actor gained access on a processing worker, escalated to node-level access, gathered cloud and cluster credentials, and moved into several internal clusters over a weekend. Hugging Face said its investigation was continuing, but it had not found evidence of changes to public user-facing models, datasets, Spaces, or its software supply chain.

The company said it fixed the initial code-execution paths, removed the attacker’s presence from affected clusters, rebuilt compromised nodes, rotated impacted credentials and other secrets, tightened cluster admission controls, and improved around-the-clock detection and alerting. It also advised customers to rotate access tokens and review recent account activity.

The report said Hugging Face used Z.ai’s GLM 5.2 open-weight model during forensic work after some hosted Western AI models declined prompts containing real attack commands and related artifacts. Hugging Face framed the episode as a warning for defenders to prepare trusted models they can run internally during incidents, both to avoid safety-filter lockouts and to keep sensitive investigation data inside their own environment.

Read the full report at Internet →

Loading debate for this article…

Other publishers covering this story

No additional verified coverage is currently clustered with this report.

Related reporting