Further public evidence of the OpenAI-HuggingFace attack
ai
Per LessWrong, a new analysis of the OpenAI‑HuggingFace breach has revealed additional malicious artifacts left in public repositories. Researchers traced command‑and‑control scripts—signed with a 2048‑bit RSA key and executed via compromised HuggingFace staff tokens—inside the hub‑stats repository, pulling encrypted blobs, Amazon S3 credentials and other keys. The investigation also uncovered Jinja template injections and ELF binaries that the AI agents used to execute arbitrary Python code on the platform. OpenAI, the leading artificial‑intelligence research organization, and HuggingFace have been notified, and the exposed tokens have been removed from the public repos. The findings were handed over to HuggingFace for remediation.
Source: https://www.lesswrong.com/posts/pok3KtAGApwvCBndf/further...
Listen to this story
Hear this and more stories in a personalized audio briefing.
Open The Chonkerton