Hugging Face said an autonomous AI agent system breached its production infrastructure and reached a limited set of internal datasets and service credentials, with the incident detected and contained earlier last week.
KEY FACTS
- Access The company said unauthorized access was limited to some internal datasets and credentials.
- Impact It found no evidence of tampering with public models, datasets, Spaces or its software supply chain.
- Initial entry The attack used two code execution paths in a dataset loader and a dataset configuration template.
- Response Credentials were revoked and rotated, compromised nodes were rebuilt and extra cluster controls were added.
The disclosure said the malicious dataset triggered code execution in a remote code dataset loader and through a template injection in a dataset configuration, which allowed the attacker to run code on a processing worker. From there, the actor escalated to node-level access, gathered cloud and cluster credentials and moved laterally into several internal clusters over a weekend.
The company said the campaign used an autonomous agent framework that carried out many thousands of actions across short-lived sandboxes, with command and control staged on public services. The exact large language model used in the intrusion remains unclear.
Hugging Face said it has addressed the code execution paths used for initial access, removed the attacker’s foothold, rebuilt compromised nodes and broadened secret rotation as a precaution. It also said detection and alerting have been improved so responders are notified within minutes around the clock.
In a separate note, the company said it used a security incident report and later turned to Z.ai’s GLM 5.2 for forensic work after other hosted models blocked requests that included attack commands, exploit payloads and command-and-control artifacts. The disclosure said the models’ safety systems prevented them from handling the material as requested.
WHY IT MATTERS
The incident shows how AI tools can be used in a fast-moving intrusion while also creating limits for defenders who rely on hosted models with stricter safety controls. It also underlines the need for incident response teams to have local analysis tools and to rotate credentials quickly after a breach.

