- Hugging Face reveals a cyberattack in which malicious code hidden in a data set exploited flaws in its systems, allowing privilege escalation and credential theft.
- The incident was unique because it was orchestrated end-to-end by an autonomous AI agent, which launched thousands of short-lived sandboxes and migrated C2 infrastructure between utilities.
- No customer data or public models were altered, but the attack highlights the emerging “agent attacker” scenario long predicted by the industry.
Hugging Face, one of the largest artificial intelligence (AI) and machine learning (ML) platforms, revealed that it recently suffered a supercharged cyberattack by an AI agent.
“This was different from anything we’d handled before in one important way: It was powered, end-to-end, by an autonomous AI agent system, and we largely detected and dissected it with our own AI,” Hugging Face explained in its announcement, noting that the attackers hid malicious code within a data set, which they then uploaded to the platform.
When Hugging Face’s automated systems processed that data set, they exploited two software flaws that allowed the attackers’ code to run on one of the company’s servers.
Orchestrated by an autonomous AI agent
This twist on the classic code injection attack allowed attackers to expand their privileges and gain more control over the system, stealing authentication credentials to access Hugging Face’s cloud infrastructure and breaking into other internal systems.
But carrying out the attack primarily with an AI agent is what made this incident unique, Hugging Face explained.
Instead of a human threat actor typing commands, Hugging Face believes the attack was orchestrated by an AI-powered autonomous agent that, entirely on its own, decided which systems to probe, which vulnerabilities to exploit, which credentials to steal, and how to move laterally across the compromised infrastructure.
“The campaign was driven by an autonomous agent framework (which appeared to be built on top of an agent security research harness; the LLM used is not yet known) that executed thousands of individual actions across a swarm of short-lived sandboxes, with self-migrating command and control organized into utilities,” Hugging Face explained. “This matches the ‘agent attacker’ scenario the industry has been predicting.”
In other words, the agent kept launching thousands of temporary computing environments, making it extremely difficult to stop the attack (since there is not a single machine to lock down). At the same time, the infrastructure controlling the malware continued to move, likely using legitimate online or public cloud services. Therefore, when defenders blocked one control server, attacks would simply come from another.
There is currently no evidence of manipulation of customer data, public user-facing models or Spaces.
The best antivirus for all budgets
Follow TechRadar on Google News and add us as a preferred source to receive news, reviews and opinions from our experts in your feeds.




