According to Beating, Hugging Face was infiltrated by autonomous AI agents using malicious datasets to execute code and steal credentials, generating over 17,000 records and performing tens of thousands of automated operations across multiple internal clusters.
Commercial frontier models declined to analyze the actual attack commands and vulnerability payloads due to safety restrictions. Hugging Face deployed the open-weight model GLM-5.2 locally to complete the security investigation. The vulnerability has been patched, affected credentials revoked, and no tampering was detected on public models, datasets, or Spaces.