Machine learning collaboration platform Hugging Face has disclosed a data breach resulting from a cyberattack conducted by an autonomous AI agent.
The attack targeted the company’s production infrastructure and resulted in unauthorized access to internal datasets and to service credentials.
According to Hugging Face, a data-processing pipeline was used as the entry point, followed by node-level escalation, credential harvesting, and lateral movement.
“A malicious dataset abused two code-execution paths in our dataset processing (a remote-code dataset loader and a template-injection in a dataset configuration) to run code on a processing worker,” Hugging Face explains.
The attackers used an autonomous framework built on an agentic security-research harness to execute tens of thousands of actions across short-lived sandboxes, and relied on public services to stage self-migrating command-and-control (C&C) capabilities.










