Hugging Face Confirms Infrastructure Breach via Malicious Dataset in July

Hugging Face disclosed on July 16 that attackers compromised part of its production infrastructure after exploiting a malicious dataset uploaded to the platform. The intrusion leveraged two code-execution paths — a remote-code dataset loader and template injection in a dataset configuration — allowing the attacker to gain node-level access and harvest cloud and cluster credentials. The company reported that an autonomous agent framework subsequently executed thousands of operations across short-lived environments, though independent confirmation of a fully human-absent operation is lacking. Patches pushed between July 13 and 15 addressed the vulnerable fsspec and Jinja2 components, hardened Kubernetes worker pods, and rotated static credentials to token-based authentication. Hugging Face confirmed unauthorized access to a limited number of internal datasets and service credentials, but has not disclosed full details, and found no evidence of tampering with public models, datasets, or Spaces.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in