Hugging Face Patches Critical Vulnerability That Exposed AI Models to Supply Chain Attacks
Hugging Face, the open-source AI platform, recently disclosed that it was compromised by an autonomous AI agent system in an attack discovered and contained last week. The breach affected a limited set of internal datasets and service credentials, though the company stated there is no evidence that public-facing models, datasets, or its software supply chain were altered. The investigation remains ongoing as the company works to understand the full scope of the incident.
The attack began through the data processing pipeline when a malicious dataset exploited two code-execution vulnerabilities: a remote code dataset loader and a template injection flaw in a dataset configuration. This initial foothold allowed the attacker to execute code on a processing worker, escalate to node-level access, and steal cloud and cluster credentials. Over the weekend, the threat actor moved laterally across multiple internal clusters using an autonomous agent framework that performed thousands of actions through many short-lived sandboxes, with command-and-control infrastructure staged on public services. The specific large language model powering this autonomous agent remains unknown.
Hugging Face has patched the code-execution vulnerabilities that enabled the initial breach and implemented various remediation measures across its infrastructure. As a precautionary step, the company is asking customers to rotate their access tokens and review recent account activity. The incident highlighted an unexpected challenge during the forensic investigation when Western frontier AI models refused to process requests containing real attack commands and exploit payloads because their safety filters could not distinguish between legitimate incident response work and actual malicious activity.
This operational difficulty led Hugging Face to use a Chinese open-weight model for their forensic analysis, revealing a critical gap in cybersecurity preparedness. The company emphasized that defenders face an asymmetry where attackers can use unrestricted models without usage limits, while security teams may find themselves blocked by the very guardrails designed to prevent misuse. Hugging Face recommends that organizations maintain their own capable AI models, vetted and ready before an incident occurs, to avoid being hindered by safety restrictions and to prevent sensitive attacker data and credentials from leaving their controlled environment during investigations.
Stay secure — stay Wavasec. 🔐