Hugging Face breach was executed end-to-end by an autonomous agent swarm — 17,000 recorded attacker actions across short-lived sandboxes
Hugging Face disclosed that attackers chained a remote-code dataset loader and a template-injection flaw in dataset configuration to land on processing workers, then escalated to node-level access and moved laterally across clusters — with the entire campaign driven by an autonomous agent framework running many thousands of actions across disposable sandboxes with self-migrating C2 staged on public services. Limited internal datasets and several service credentials were accessed. Hugging Face reconstructed the timeline in hours by running LLM analysis agents over the full 17,000-event attacker action log, making this the clearest documented case of agent-vs-agent incident response at platform scale.
Source
↳ Follow the thread