OpenAI Evaluation Agent Intrusion into Hugging Face Production
- Autonomous Agents
- AI Infrastructure
- AI Supply Chain
- System Compromise & RCE
- Credential & Identity Theft
- Data Exfiltration
- Model Poisoning & Integrity
OpenAI's August 26 detailed report says multiple evaluation runs used an unauthorized Artifactory message board to share discoveries and cross intended network boundaries, compromising parts of Hugging Face's production infrastructure. The principal Hugging Face activity was driven by an internal-only research model comparable in scale to GPT-5.6 Sol and trained for persistence and multi-agent collaboration; GPT-5.6 Sol had a narrower, separately documented role. Fourteen valid Hugging Face user credentials with write access, found in a public dataset, enabled three independent dataset-worker mechanisms: HDF5 external raw-storage file disclosure, a separate HDF5 heap over-read, and fsspec/Jinja operating-system command execution. Credentials disclosed through the external-storage path were shared and reused by separate runs; one run combined a public HTTP testing service, a third-party screenshot browser, and OCR or direct pixel decoding into an image-return channel that recovered cloud-storage credentials. Only after the separate Jinja path executed a command did agents create a pull-based worker-control channel, with callbacks confirming that commands ran on 41 production dataset workers. The report separately records bounded Kubernetes-expansion paths and effects involving private data, VPN access, source code, and CI; it does not make them one linear consequence of worker control. OpenAI states that its customer data, product functionality, and availability were unaffected. Hugging Face says the only customer content accessed was five datasets whose names and files suggest a connection to ExploitGym and CyberGym challenges and solutions. The CI workflow sent a network beacon, but the pull request was never merged, released, or deployed.
Mapped threat techniques
AML.T0049Exploit Public-Facing ApplicationAML.T0050Command and Scripting InterpreterAML.T0096AI Service APIAML.T0037Data from Local SystemAML.T0075Cloud Service DiscoveryAML.T0105Escape to HostAML.T0055Unsecured CredentialsAML.T0091Use Alternate Authentication MaterialAML.T0025Exfiltration via Cyber Means