Massive cyber incident at Hugging Face: Hundreds of thousands of users at risk
Attackers took over the account of a well-known developer on the popular AI model sharing platform and injected malicious code into dozens of common open-source libraries. The incident could affect thousands of organizations and hundreds of thousands of users worldwide. Security experts urge caution.

A massive information security incident has shaken the development world as researchers from the cybersecurity company Upwind revealed that dozens of popular open-source libraries by a developer known as Keyv on the Hugging Face platform were contaminated with malicious code. The developer is considered highly prolific, and the libraries he developed have collectively recorded hundreds of millions of downloads worldwide.
According to Upwind's initial research, attackers managed to take over Keyv's identity and used the access to inject malicious code into the latest updates of the libraries he contributes to. The code was designed to steal usernames and passwords, posing a grave threat to digital security.
Updated estimates indicate that thousands, perhaps tens of thousands, of organizations worldwide, along with hundreds of thousands of their customers, may be exposed to a severe supply chain attack. The incident involves approximately 1,500 libraries. According to the company, such an incident has the potential to statistically affect between 50% and 60% of all organizations globally. The full extent of the damage will be revealed in the coming hours.
Security experts recommend that organizations and development teams re-examine their implemented versions and halt automatic updates until the situation is clarified.
Dan Yahav, SVP of Platforms at Upwind, stated: "What happened here is identity theft of a leading developer from Seattle. The attackers took advantage of the late-night hours to insert new features and updates into many libraries without approval. Malicious code was injected to steal passwords directly from the infrastructures installing these libraries." He noted that while they attempted to reach the developer, the malicious code continued to spread through a wide supply chain.
When an infected version is installed, the malicious code activates automatically.
The platforms hosting these libraries have identified the global attack and have begun removing the products to stop distribution. "Our unequivocal recommendation is not to rush to install the latest software updates. Many companies pull updates automatically, but right now you must stop, ensure everything is in order, and not install new versions immediately," Yahav explains.
Gil Messing, Chief of Staff and Head of Global Communications at Check Point, explained: "These components are used by thousands of systems, and some are installed hundreds of millions of times a month. When a developer or system installs an infected version, the code activates automatically during installation—without the need for the user to open a file or click a link." Messing added that the goal is to steal access permissions, including GitHub accounts, AWS infrastructure keys, HashiCorp Vault secret management systems, and passwords saved in development environments.
What can be done? Messing advises temporarily stopping automatic updates, checking if the organization used the affected packages, and looking for signs of infection within the company. In the long term, he suggests implementing restrictive settings that prevent immediate installation of new packages, allowing for a testing interval before deployment.





