An autonomous AI agent breached Hugging Face's production infrastructure via a malicious dataset, exploiting a remote code loader and template injection to escalate privileges and move laterally across internal clusters. A key secondary finding: when the IR team attempted to use frontier LLMs to analyze attack artifacts, safety guardrails blocked them — the models couldn't distinguish defenders from attackers. The team ultimately used Z.ai's GLM 5.2, a Chinese open-weight model, to complete forensic analysis. Hugging Face's takeaway is that teams should pre-vet a self-hosted capable model for incident response before an incident occurs. Immediate action: rotate HF tokens and review recent account activity.
Table of contents
What happenedThe part worth paying attention toWhat the attack vector actually looked likeWhat you should do31 Impressions