Skip to content
AI SecuritySupply ChainLLMopen-source-security

Hugging Face's trending algorithm became a malware delivery vector

3 min read
Share

AI supply chain attacks on HuggingFace: what the HiddenLayer research reveals

HiddenLayer, the AI security firm, published research this week documenting a systematic supply chain attack pattern targeting the HuggingFace model hub. Attackers are uploading models that appear legitimate but embed malicious serialization payloads capable of executing arbitrary code when the model is loaded by a downstream developer or automated pipeline. The findings underscore a gap that traditional application security controls do not address.

The attack vector

The primary delivery mechanism is pickle serialization, the default format for PyTorch model weights. Because pickle files can execute arbitrary Python code during deserialization, a model file that appears valid in the HuggingFace UI can silently run attacker-controlled code the moment it is loaded via a call like torch.load() or model.from_pretrained(). HiddenLayer's scan identified dozens of accounts with upload histories showing patterns consistent with deliberate poisoning rather than accidental misconfiguration.

Why this is harder to detect than traditional supply chain attacks

Traditional SCA (Software Composition Analysis) tools look for known-malicious package hashes or dependency confusion patterns. They are not designed to parse binary model weight files and cannot inspect pickle bytecode for shell commands or network callbacks. An organization that has mature dependency scanning in its CI pipeline will still load a malicious HuggingFace model without any alert firing, because the model arrives as a large binary blob that no standard gate evaluates.

HuggingFace's countermeasures and their limits

HuggingFace has deployed automated scanning that flags some pickle-based payloads and displays a safety warning on affected model pages. However, the platform hosts millions of model files and the scanning coverage is incomplete. Attackers have demonstrated the ability to obfuscate payloads in ways that bypass the current scanner. HuggingFace's safer alternative format, safetensors, prevents code execution during load, but many published models have not migrated and the from_pretrained API will still load pickle-format weights if a safetensors version is unavailable.

Practical steps for teams using HuggingFace models

Prefer safetensors format when it is available for a model and pin the specific commit hash rather than pulling the latest revision. Run all model loading in an isolated environment (a container with no network egress and no access to production credentials) before promoting a model to any pipeline that touches sensitive systems. Use picklescan or a similar tool to audit any pickle-format weights before loading. Establish an internal model registry so that approved, scanned versions are what production systems pull, rather than allowing direct downloads from HuggingFace in runtime environments.

Gigia Tsiklauri is a Security Architect and founder of Infosec.ge. Get in touch if your team is building AI pipelines and wants a security review of your model supply chain controls.