What changed: This version adds details from Edward Cant’s new analysis about publicly exposed keys and control-channel code.

In a new analysis, researcher Edward Cant writes that he coordinated with the Hugging Face team to remove publicly exposed keys from repositories. Cant says the keys were found while examining additional traces of the incident that remained public.

Cant included code for a control channel that, after checking a command signature, executed the command and wrote an encrypted result. Cant believes these artifacts show that the attack scripts were refined as access to the target grew.

Claim check:

  • Edward Cant reported that he coordinated with the Hugging Face team to remove publicly exposed keys from repositories. (confirmed by the publication itself: evidence; «We also came across some exposed keys being publicly served, which we then coordinated with HF to help get them all removed from public repositories.»)
  • According to Cant, the keys were found while examining additional traces of the incident that remained publicly accessible. (confirmed by the publication itself: evidence; «The huggingface hacking incident left some additional traces exposed to the public. Investigating this data gave us some additional insight into the attacks performed by the AI agents.»)
  • Cant included code for a control channel that, after checking a command signature, executed the command and wrote an encrypted result. (confirmed by the publication itself: evidence; «If the command has a different hash than the previous one and the signature is valid, the command is executed and the result written, encrypted, to ddsours/c2/out.txt»)
  • Cant believes these artifacts show that the attack scripts were refined as access to the target grew. (confirmed by the publication itself: evidence; «Based on timestamps in metadata, exploring these artifacts indicated a process of refinement. The attacks scripts improved as the agents gained higher levels of privilege and more control over the target:»)

Publications:

Primary sources:

score 79.7 out of 100 · kind: incident · update 41