Hugging Face Hacked in Autonomous AI Attack

Machine learning collaboration platform Hugging Face has disclosed a data breach resulting from a cyberattack conducted by an autonomous AI agent.
The attack targeted the company’s production infrastructure and resulted in unauthorized access to internal datasets and to service credentials.
According to Hugging Face, a data-processing pipeline was used as the entry point, followed by node-level escalation, credential harvesting, and lateral movement.
“A malicious dataset abused two code-execution paths in our dataset processing (a remote-code dataset loader and a template-injection in a dataset configuration) to run code on a processing worker,” Hugging Face explains.
The attackers used an autonomous framework built on an agentic security-research harness to execute tens of thousands of actions across short-lived sandboxes, and relied on public services to stage self-migrating command-and-control (C&C) capabilities.
Hugging Face says it responded to the attack largely with its own AI, addressed the dataset code-execution paths exploited for initial access, evicted the attackers from its infrastructure, rebuilt the affected nodes, and revoked and rotated all affected credentials.
As a precaution, it also started broadly revoking secrets, deployed stricter admission controls and additional guardrails, and improved detection and alerting.
The company reported the incident to law enforcement and is investigating it in collaboration with outside cybersecurity forensic specialists.
“We have found no evidence of tampering with public, user-facing models, datasets, or Spaces, and our software supply chain (container images and published packages) was verified clean,” Hugging Face says.
The company says its systems logged over 17,000 events associated with the intrusion and ran agentic analysis to reconstruct the incident timeline and determine its scope. However, it could not determine the LLM that the threat actor used to automate the attack.
“Autonomous, AI-driven offensive tooling is no longer theoretical. It lowers the cost of running a broad, patient, multi-stage campaign, and it operates at machine speed. Defending an online platform now means treating the data and model surface as a first-class attack surface, and using AI on defense to keep pace,” the company notes.
Related: AI Data Centers Are Being Built Faster Than They Can Be Secured
Related: Unpatched Cursor Vulnerability Exposes Users to Code Execution
Related: White House Launches AI-Driven ‘Gold Eagle’ Vulnerability Coordination Initiative
Related: Unpatched Claude for Chrome Flaw Lets Extensions Read Gmail, Calendar
https://www.securityweek.com/hugging-face-hacked-in-autonomous-ai-attack/