- Hugging Face reveals a cyberattack in which malicious code stored in a dataset exploited flaws in its systems, enabling privilege escalation and credential theft
- The incident was unique in being orchestrated end-to-end by an autonomous AI agent, which launched thousands of short-lived sandboxes and migrated C2 infrastructure across public services
- No customer data or public models were tampered with, but the attack highlights the new “agentic attacker” scenario that the industry has long predicted
Hugging Face, one of the largest artificial intelligence (AI) and machine learning (ML) platforms, recently revealed that it was the victim of a cyber attack carried out by an AI agent.
“This one was different from anything we’d handled before in one important way: it was run end-to-end by an autonomous AI agent system — and we discovered and dissected it largely with our own AI,” Hugging Face explained in its announcement, noting that the attackers hid malicious code inside a dataset that they then uploaded to the platform.
When Hugging Face’s automated systems processed this data set, they exploited two software flaws that allowed the attackers’ code to run on one of the company’s servers.
Orchestrated by an autonomous AI agent
This twist to the classic code injection attack allowed the attackers to escalate their privileges and gain more control over the system, stealing authentication credentials to access Hugging Face’s cloud infrastructure and pivoting to other internal systems.
But carrying out the attack mostly with an AI agent is what made this incident unique, Hugging Face explained.
Instead of a human threat actor writing commands, Hugging Face believes the attack was orchestrated by an AI-powered autonomous agent that decided on its own which systems to probe, which vulnerabilities to exploit, which credentials to steal, and how to move laterally through the compromised infrastructure.
“The campaign was powered by an autonomous agent framework (which appears to be built on an agent security research harness – used LLM is still unknown) that executes many thousands of individual actions across a swarm of short-lived sandboxes, with self-migrating command-and-control staged on public services,” Hugging Face explained. “This matches the ‘agentic attacker’ scenario that the industry has been predicting.”
In other words, the agent kept launching thousands of temporary computing environments, making it extremely difficult to stop the attack (since there is not a single machine to block). At the same time, the infrastructure controlling the malware continued to move, likely using legitimate public cloud or online services. Therefore, when the defenders blocked one control server, the attacks would simply come from another.
There is currently no evidence of tampering with customer data, public user-facing models or Spaces.
The best antivirus for all budgets
Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews and opinions in your feeds.



