After the incident, Hugging Face shut down the vulnerable code execution paths, rebuilt affected systems, revoked compromised credentials, strengthened cluster security controls, and enhanced detection and alerting systems. The company also stated it is working with external cybersecurity forensic experts and has reported the incident to law enforcement. As a precaution, Hugging Face recommends users rotate access tokens and review recent account activity.
The company is still investigating whether any customer or partner information was affected and will notify relevant parties directly if necessary. So far, no evidence has been found of tampering with public models, datasets, Spaces, container images, or published software packages.