Hugging Face reports intrusion carried out by AI agents

Hugging Face has disclosed an intrusion into part of its production infrastructure, stating the attack was conducted end to end by an autonomous AI agent system. A malicious dataset abused a vulnerability to execute code on a processing worker, steal cluster credentials and move laterally across internal clusters. The company found unauthorised access to limited internal datasets and service credentials, but no evidence that public models, datasets, Spaces, container images or published packages were modified. Hugging Face has closed the vulnerable code-execution paths, rebuilt compromised nodes, rotated credentials and strengthened cluster controls, and advises users to rotate access tokens and review recent account activity.

What this means for you if you build with models and agents

The sequence will look familiar if you have seen this kind of attack before. Malicious input leads to code execution. Code execution yields credentials, and credentials open the way further in. Berigo's assessment is that the novelty is not the technique but the pace and scale when the whole chain is driven by agents with no human in the loop. If you pull models or datasets from public registries, it is worth knowing that you are taking in code from an unknown source.

If you build agent-based systems yourself, our position is that isolation and least privilege apply in full. An agent is running code. Being new gives it no claim to more trust than any other running code. It should not be handed wider access either. The point that matters most, in our view, is knowing what your processing environments can actually reach. That access decides how far an attack gets.

Berigo recommends

  • Process external models and datasets in isolated environments with no access to production credentials.
  • Rotate access tokens for Hugging Face and review account activity for the projects involved.
  • Include agent-driven and AI-enabled attacks as a distinct scenario in your risk assessment, not merely a variant of existing threats.
  • Time-limit service credentials so that a theft comes with an expiry date.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch