HackMyIP
← Back to News
2026-07-20 The Hacker News

Autonomous AI Agent Hacks Hugging Face in Landmark Model Hub Breach

AI SecurityData BreachVulnerability

In a striking case of the defender becoming the target, Hugging Face, the world's largest open-source AI model repository, disclosed on July 20, 2026, that an autonomous AI agent system compromised its production infrastructure earlier this month. The New York-headquartered company confirmed "unauthorized access to a limited set of internal datasets and to several credentials used by our services," though it emphasized that an ongoing investigation has found no evidence of tampering with public models, datasets, Spaces, or its software supply chain. The incident underscores a new reality in which offensive AI capabilities rival defensive tooling, and it spotlights gaps in incident-response preparation.

The attacker's entry point was Hugging Face's own data processing pipeline. A malicious dataset exploited two code-execution paths: a remote code dataset loader and a template injection vulnerability in a dataset configuration file, enabling arbitrary code execution on a processing worker. From that initial foothold, the threat actor escalated to node-level access, harvested cloud and cluster credentials, and pivoted laterally across several internal clusters over a single weekend. Hugging Face described the campaign as the work of "an autonomous agent framework performing many thousands of individual actions across a swarm of short-lived sandboxes, with self-migrating command-and-control staged on public services," though the specific large language model (LLM) driving the attack remains unidentified.

In an unusual twist, Hugging Face's forensic team turned to Z.ai's GLM 5.2, a Chinese open-weight model, after Western frontier LLMs refused to process authentic attack commands, exploit payloads, and C2 artifacts due to their safety guardrails. "We do not know which model powered the attacker's agents, whether a jailbroken hosted model or an unrestricted open-weight one; either way, the attacker was bound by no usage policy, while our own forensic work was blocked by the guardrails of the hosted models we first tried," the company noted. Remediation steps included purging attacker footholds across affected clusters, rebuilding compromised nodes, rotating affected credentials and secrets, and tightening admission controls with 24/7 detection alerting.

Users should immediately rotate any access tokens and review recent account activity as a precaution, especially those who use a strong password checker to validate their credentials. Those concerned about broader exposure can run an email breach checker on associated accounts, while a full privacy checkup helps surface lingering exposures across tokens and services. Hugging Face's experience illustrates that defenders need unrestricted analytical models pre-approved for incident-response work, before an adversary's autonomous agents force the issue.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is a data breach? →Credential stuffing attacks →How to check for an email breach →