Hugging Face hit by network compromise
Incident
Summary
Hide ▲
Show ▼
Hugging Face confirmed a production infrastructure breach that exposed a limited set of internal datasets and service credentials, creating risk of further internal access. The intrusion began through malicious dataset code execution paths in a remote code loader and a template injection in a dataset configuration. The company said it found no evidence the attacker tampered with public models, datasets, or Spaces.
Related Happenings
TrustBastion Android malware campaign abusing Hugging Face for credential theft
Campaign
H score37
First: 30.01.2026 00:08
Last: 30.01.2026 00:08
Sources 1
About this happening:
A new Android malware campaign is abusing Hugging Face as distribution infrastructure to deliver polymorphic APKs that steal credentials from users of financial and...
TrustBastion Android malware campaign abusing Hugging Face for credential theft
CampaignAbout this happening: A new Android malware campaign is abusing Hugging Face as distribution infrastructure to deliver polymorphic APKs that steal credentials from users of financial and...
Timeline
-
20.07.2026 08:27 3 articles · 17h ago
Hugging Face detects unauthorized access to internal datasets and service credentials
Initial DisclosureHugging Face said it detected and responded to a production-infrastructure intrusion earlier last week that resulted in unauthorized access to a limited set of internal datasets and several service credentials. The company said the compromise began in the data processing pipeline, where a malicious dataset abused a remote code dataset loader and a template injection in a dataset configuration to run code on a processing worker; it later addressed the root cause, rebuilt compromised nodes, revoked and rotated affected credentials and tokens, tightened cluster controls, and urged customers to rotate access tokens and review account activity.
Show sources
- World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent — thehackernews.com — 20.07.2026 08:27
- World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent — thehackernews.com — 20.07.2026 08:27
- Hugging Face discloses breach linked to autonomous AI agent — www.bleepingcomputer.com — 20.07.2026 14:56