- Hugging Face reveals a cyberattack in which malicious code hidden in a dataset exploited flaws in its systems, enabling privilege escalation and credential theft.
- The incident was unique in that it was orchestrated end-to-end by an autonomous AI agent, which launched thousands of short-lived sandboxes and migrated C2 infrastructure across utilities.
- No customer data or public models were tampered with, but the attack highlights the emerging scenario of an “agent attacker” long predicted by the industry.
Hugging Face, one of the largest artificial intelligence (AI) and machine learning (ML) platforms, recently revealed that it suffered a supercharged cyberattack by an AI agent.
“This was different from anything we had dealt with before in one important way: It was driven, end to end, by an autonomous AI agent system – and we detected and dissected it largely with our own AI,” Hugging Face explained in its announcement, noting that the attackers hid malicious code in a dataset, which they then uploaded to the platform.
When Hugging Face’s automated systems processed this data set, they exploited two software flaws that allowed the attackers’ code to run on one of the company’s servers.
Orchestrated by an autonomous AI agent
This variation of the classic code injection attack allowed the attackers to expand their privileges and gain greater control over the system, steal credentials to access Hugging Face’s cloud infrastructure, and pivot to other internal systems.
But carrying out the attack primarily with an AI agent is what made this incident unique, Hugging Face explained.
Instead of a human actor typing commands, Hugging Face believes the attack was orchestrated by an autonomous AI-powered agent who, all on its own, decided which systems to probe, which vulnerabilities to exploit, which credentials to steal, and how to move laterally through the compromised infrastructure.
“The campaign was run by an autonomous agent framework (appearing to be built on an agent security research harness – used LLM as yet unknown) executing several thousand individual actions across a swarm of short-lived sandboxes, with auto-migrating command and control staged across utilities,” Hugging Face explained. “This fits the ‘agent attacker’ scenario that the industry was predicting.”
In other words, the agent continued to launch thousands of temporary computing environments, making it extremely difficult to stop the attack (since there is not a single machine to block). At the same time, the infrastructure controlling malware has continued to evolve, likely using legitimate public cloud or online services. Therefore, when defenders blocked one controlling server, attacks simply came from another.
There is currently no evidence of tampering with customer data, public user templates, or spaces.
The best antivirus for every budget
Follow TechRadar on Google News And add us as your favorite source to get our news, reviews and expert opinions in your feeds.




