Skip to content
Back to stories
Industry

Malware Hides Inside AI Model Repositories on Hugging Face

Malware Hides Inside AI Model Repositories on Hugging Face
Image: Acronis

Acronis Threat Research Unit has identified in-the-wild attacks using AI distribution platforms, specifically Hugging Face and ClawHub, to deliver malware. Attackers disguise malicious code as models, datasets, and agent extensions. Hugging Face alone hosts over one million machine learning models.

This is not a traditional supply chain attack. Acronis notes the campaigns exploit trust inside AI ecosystems and agent workflows, meaning malicious actions can propagate beyond the initial infected system. The dependency on shared, centralized artifact repositories, rarely validated deeply, is the structural weakness being exploited.

Any operator pulling models or datasets from public repositories without verification controls is exposed. Watch for platform-level responses from Hugging Face and for whether enterprise AI procurement policies begin requiring artifact provenance checks. The distribution layer is now an attack surface.