Hugging Face, the world’s largest open-source artificial intelligence (AI) repository, has revealed that it was hit by a sophisticated hacking attack driven entirely by an “AI agent”. Hugging Face has also disclosed that after the US-made models blocked requests to neutralise the attack due to guardrails, they used an open-weight AI model from China to mitigate the attack.
Hugging Face explains how AI attack unfolded
According to Hugging Face, the breach began in a vulnerability specific to AI hosting infrastructure: the data-processing pipeline. A malicious dataset injected into the system exploited two separate code-execution flaws. Once inside, the autonomous AI agent escalated its access to gain control over internal server nodes, harvested security credentials and moved laterally across several internal server clusters over a weekend.Notably, it was the scale and speed of the hacking incident that caught the attention. According to Huggin Face, the hacker deployed an autonomous agent framework that executed thousands of coordinated actions across a fleet of temporary sandboxes.Secondly, the AI system dynamically shifted its command-and-control operations across public cloud services to evade traditional security filters. Hugging Face confirmed that while unauthorised access to a limited set of internal datasets and service credentials occurred, there is no evidence that public user-facing models, datasets or software packages were tampered with.“The intrusion started where AI platforms are uniquely exposed: the data-processing pipeline. A malicious dataset abused two code-execution paths in our dataset processing (a remote-code dataset loader and a template-injection in a dataset configuration) to run code on a processing worker,” the company said.
‘AI safety guardrails blocked defenders’
When Hugging Face engineers rushed to analyse server logs, they hit a roadblock. The team initially tried using commercial, top-tier AI models via cloud APIs to analyse the malicious code. However, the safety guardrails built into these commercial AI services flagged the actual attack payloads as harmful content, instantly locking out the cybersecurity responders. To bypass the lockout, Hugging Face ran GLM 5.2 – an open-weight AI model by Chinese technology company Z.ai – locally on its own private infrastructure. This allowed defenders to analyse the malicious attack data freely while ensuring sensitive internal tokens never left their secure environment.“The attacker was bound by no usage policy, while our own forensic work was blocked by the guardrails of the hosted models we first tried,” Hugging Face noted, pointing out a critical gap in corporate cybersecurity.
Click Here For The Original Source.
