Hugging Face warns an autonomous AI agent hacked its network
Key Points:
- Hugging Face revealed that attackers used an autonomous AI agent system to breach its production infrastructure, gaining access to internal datasets and credentials through exploiting code-execution vulnerabilities in its data-processing pipeline.
- The attackers leveraged a malicious dataset to run code on a processing worker, stealing cloud and cluster credentials and moving laterally across internal clusters, with the campaign involving thousands of actions by an autonomous agent framework.
- Hugging Face has closed the vulnerable code execution paths, evicted the attacker, rebuilt compromised nodes, rotated credentials, and enhanced malicious activity detection while working with forensic experts and law enforcement.
- The company has found no evidence of tampering with public-facing models or datasets and is still investigating potential impacts on partner or customer data, pledging to notify affected parties directly.
- Users are advised to rotate access tokens and monitor account activity for suspicious behavior, as Hugging Face continues to share insights on defending against AI-driven attacks following this first AI agent-linked security incident on the platform.