Research

Hugging Face Attack Chain Part 1: You Cannot Detect a Malicious Model. Detect What It Does Next. | Community

Page published

Publication date unknown · First observed: 11 Oct 2026

Coverage timeline

11 Oct 2026securonix.comobserved

Single-source research — one report is available.

Why it matters

Malicious ML models exploit pickle/torch.load as executable content that cannot be detected from cluster logs, turning model uploads into remote code execution and cloud credential theft in multi-tenant AI inference environments.

Securonix reproduces Wiz Research's Hugging Face attack chain in which a cloned gpt2 model is modified so that loading it executes attacker code via pickle deserialization, gaining execution inside an Amazon EKS pod. From there the pod reaches the EC2 Instance Metadata Service (169.254.169.254) to steal the worker node's IAM credentials, obtains a Kubernetes token via aws eks get-token, and enumerates pods and secrets; related research against Hugging Face Spaces reached a shared container registry with write access.