Hugging Face, the world’s largest open-source AI model repository, disclosed a security breach perpetrated by an autonomous AI agent system. The attack targeted the company’s production infrastructure, exploiting code execution paths in its data processing pipeline to gain initial access. The threat actor used a malicious dataset to abuse the remote code dataset loader and a template injection in a dataset configuration, enabling code execution on a processing worker. From there, the attacker escalated privileges to node-level access, collected cloud and cluster credentials, and moved laterally across multiple internal clusters over a weekend.
Hugging Face stated that the campaign involved an autonomous agent framework performing thousands of individual actions across a swarm of short-lived sandboxes, with self-migrating command-and-control staged on public services. The company has since addressed the root cause, removed the attacker’s foothold, rebuilt compromised nodes, rotated credentials, and deployed additional guardrails and detection measures. It urged customers to rotate access tokens and review account activity.
Notably, Hugging Face turned to Z.ai’s GLM 5.2, a Chinese open-weight model, for forensic analysis after Western frontier models refused requests containing real attack commands and C2 artifacts due to safety guardrails. The incident highlights a gap for defenders: having a capable, unrestricted model ready for incident response to avoid guardrail lockout and keep sensitive data within the environment.
Companies: Hugging Face, Z.ai
Products: GLM 5.2
Original source: thehackernews.com