Hugging Face says an autonomous AI agent breached its production infrastructure
Hugging Face disclosed that an intrusion driven end-to-end by an autonomous AI agent exploited two code-execution flaws in its dataset pipeline to reach internal clusters and credentials, executing more than 17,000 logged actions before being contained.
- Victim
- Hugging Face
On 16 July 2026, Hugging Face β the New York-headquartered company that operates the world's largest open-source repository of AI models, datasets and applications β disclosed that part of its production infrastructure had been breached by an intrusion driven end-to-end by an autonomous AI agent system. In a public security-incident write-up, the company said the attack executed more than 17,000 individual logged actions across a swarm of short-lived sandboxes before it was detected and contained.
According to Hugging Face, the intrusion began in its dataset-processing pipeline: a malicious dataset abused two code-execution paths β a remote-code dataset loader and a template-injection flaw in dataset configuration β to run code on a processing worker. From that foothold the attacker escalated to node-level access, harvested cloud and cluster credentials, and moved laterally into several internal clusters over a weekend, with self-migrating command-and-control staged on public services.
Internal access, but public assets reported clean
Hugging Face said the attacker gained unauthorised access to a limited set of internal datasets and to several credentials used by its services. Critically, the company reported no evidence of tampering with public, user-facing models, datasets or Spaces, and said its software supply chain β container images and published packages β had been verified clean. That distinction was central to the disclosure: a compromise of the public repository or its build pipeline could have poisoned models downloaded by millions of developers, whereas the confirmed impact was confined to internal systems.
An AI-driven attack met with AI-assisted defence
The incident is notable as one of the first publicly documented intrusions of a major platform driven end-to-end by an autonomous agent rather than a human operator working interactively. Hugging Face said the attack was first surfaced by an LLM-based triage system running over its security telemetry, and that analysts used LLM-driven agents to reconstruct the timeline from the full 17,000-event action log, extract indicators of compromise and separate genuine impact from decoy activity. The company said it fixed the exploited vulnerabilities, eradicated the attacker's foothold, revoked affected credentials, rebuilt compromised nodes and deployed additional controls. The model or operator behind the autonomous agent was not identified, and no attribution was offered at the time of disclosure.
Timeline
Hugging Face publishes a security-incident disclosure describing an intrusion into part of its production infrastructure that was driven end-to-end by an autonomous AI agent system.
The company says the attack began in its dataset-processing pipeline via a malicious dataset that abused a remote-code dataset loader and a template-injection flaw to run code on a worker, then escalated to node-level access, harvested cloud and cluster credentials and moved laterally into several internal clusters over a weekend.
Hugging Face reports it contained the intrusion after analysing more than 17,000 logged attacker actions, found no evidence of tampering with public models, datasets or Spaces, and rebuilt compromised nodes, revoked credentials and deployed additional controls.
Sources
- huggingface.cohttps://huggingface.co/blog/security-incident-july-2026
- bleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/hugging-face-breach-autonomous-ai-agent-system-internal-datasets-credentials/
- thehackernews.comhttps://thehackernews.com/2026/07/worlds-largest-ai-model-repository.html
- securityweek.comhttps://www.securityweek.com/hugging-face-hacked-in-autonomous-ai-attack/
- hackread.comhttps://hackread.com/hugging-face-ai-agent-breach-production-system/