Overview
- Hugging Face disclosed Monday that an autonomous AI agent framework accessed a limited set of internal datasets and several service credentials and that the company has closed the initial attack paths.
- The attackers began in the dataset-processing pipeline by abusing two code-execution flaws — a remote-code dataset loader and a template-injection in dataset configuration — to run code on a processing worker.
- The agentic campaign executed many thousands of short-lived sandboxed actions, escalated to node-level access, harvested cloud and cluster credentials, and moved laterally across internal clusters over a weekend.
- Hugging Face used LLM-driven analysis agents to review more than 17,000 attacker actions, and said commercial hosted models blocked forensic queries so it ran Z.ai’s open-weight GLM 5.2 on-prem to complete the investigation.
- The company rebuilt compromised nodes, rotated affected credentials, tightened cluster controls, engaged external forensics and law enforcement, and is still assessing whether any partner or customer data was exposed while advising users to rotate tokens and check account activity.