Malicious AI models on Hugging Face backdoor users’ machines

At least 100 instances of malicious AI ML models were found on the Hugging Face platform, some of which can execute code on the victim’s machine, giving attackers a persistent backdoor.

Hugging Face is a tech firm engaged in artificial intelligence (AI), natural language processing (NLP), and machine learning (ML), providing a platform where communities can collaborate and share models, datasets, and complete applications.

JFrog’s security team found that roughly a hundred models hosted on the platform feature malicious functionality, posing a significant risk of  data breaches and espionage attacks.

This happens despite Hugging Face’s security measures, including malware, pickle, and secrets scanning, and scrutinizing the models’ functionality to discover behaviors like unsafe deserialization.

Achieving code execution via an AI model
Achieving code execution via an AI model (JFrog)

Malicious AI ML models

JFrog developed and deployed an advanced scanning system to examine PyTorch and Tensorflow Keras models hosted on Hugging Face, finding one hundred with some form of malicious functionality.

“It’s crucial to emphasize that when we refer to “malicious models,” we specifically denote those housing real, harmful payloads,” reads the JFrog report.

“This count excludes false positives, ensuring a genuine representation of the distribution of efforts towards producing malicious models for PyTorch and Tensorflow on Hugging Face.”

Payload types found in malicious models
Payload types found in malicious models (JFrog)

One highlighted case of a PyTorch model that was uploaded recently by a user named “baller423,” and which has since been removed from HuggingFace, contained a payload that gave it the capability to establish a reverse shell to a specified host (210.117.212.93).

The malicious payload used Python’s pickle module’s “__reduce__” method to execute arbitrary code upon loading a PyTorch model file, evading detection by embedding the malicious code within the trusted serialization process.

Payload that establishes a reverse shell
Payload that establishes a reverse shell (JFrog)

JFrog found the same payload connecting to other IP addresses in separate instances, with the evidence suggesting the possibility of its operators being AI researchers rather than hackers. However, their experimentation was still risky and inappropriate.

The analysts deployed a HoneyPot to attract and analyze the activity to determine the operators’ real intentions but were unable to capture any commands during the period of the established connectivity (one day).

Setting up honeypot to entrap the attacker
Setting up honeypot to entrap the attacker (JFrog)

JFrog says some of the malicious uploads could be part of security research aimed at bypassing security measures on Hugging Face and collecting bug bounties, but since the dangerous models become publicly available, the risk is real and shouldn’t be underestimated.

AI ML models can pose significant security risks, and those haven’t been appreciated or discussed with proper diligence by stakeholders and technology developers.

JFrog’s findings highlight this problem and call for elevated vigilance and proactive measures to safeguard the ecosystem from malicious actors.

Source link

Visited 1 times, 1 visit(s) today

Related Article

Motorola’s Souped-Up Folding Phone Is Almost Half Off

For a limited time, you can grab the Motorola Razr Ultra with 16 GB of memory and 512 GB of storage for just $700, a $600 discount from its usual price. It’s our favorite folding smartphone, with excellent performance, full-day battery life, and all the trappings you’d expect from a phone that doesn’t also fold

Unlocking app growth with true consumer behavior

Understanding user behavior has never been more complex — or more critical. While most app teams rely on first-party data, that view is inherently limited, capturing only what happens within their own ecosystem. This white paper explores what’s missing: the full consumer journey across apps, the web, and increasingly, AI-driven touchpoints. Drawing on RealityMine’s cross-platform

Georgia AG Chris Carr Ready to Shoot Down Drones to Stop Cell Phone Drops in State Prisons

💡 ■ Circle City’s McCoy Had ‘Cordial and Constructive’ Meeting with Gomez ■ Amazon Leo’s ‘Performance Will Be Stronger’ Than Starlink’s, CEO Jassy Says ■ DOJ Looking at Consumer Impact of NFL Streaming Deals ■ Anchorage Bans Data Centers in ‘Residential Zones’ ■ American Consumer Institute: U.S. Needs Data Privacy Law ASAP’ ■ Copper Theft Concentrated

The integrated growth engine – Business of Apps

Back 2018, Andy Carvell, Co-Founder and CEO at Phiture, was already asking app teams an uncomfortable question: are you working in silos? More than half the room at his Business of Apps Berlin back then session put their hands up. Seven years later, in 2025, he asked the same question in the same room. The

Versinetic identifies trends shaping UK EV charging market

Looking ahead to 2026 and beyond, the company said the sector is approaching a tipping point at which operational shortcomings and failures to meet compliance standards could carry substantial financial consequences for charge point operators. One of the most immediate pressures comes from the UK’s legally mandated 99 per cent uptime requirement for rapid chargers.

U.S. Restricts Chinese EV Access to American Market

Got story updates? Submit your updates here. › The U.S. government’s restrictions on Chinese electric vehicle technology could impact cross-border travel and personal use near the border.Warren Today The U.S. government plans to maintain strict barriers to Chinese electric vehicles entering the American market, citing national security risks from certain Chinese-made software and hardware. This

Hyundai reboots China market strategy with EV brand Ioniq

Hyundai is introducing the Ioniq brand to China and will unveil its first production model for the Chinese market at the Beijing Auto Show later this month. New energy concept vehicles named Venus Concept and Earth Concept make their global debut. (Image credit: Hyundai Motor) Hyundai Motor has introduced its electric vehicle (EV) brand Ioniq

Denza brings super-fast charging to European luxury EV market

BYD, the biggest name in Chinese electric cars, is bringing its high-end brand, Denza, to the European luxury EV market. The company held a big event at the Palais Garnier in Paris to show off its newest EVs. The Chinese car makers are clearly serious about competing with European brands on their own territory. But

EVs Are Out of the Headlines and That’s Exactly Why These 2 Stocks Are Buys

The electric vehicle (EV) market expanded rapidly from 2020 to 2023, but its growth cooled off over the past three years. Reduced government subsidies, saturation of the early adopter market, rising rates, and other macro headwinds caused that slowdown. The EV market is still expanding, but many investors are still shunning EV stocks in this

Medicare’s Health Tech Ecosystem initiative previews new apps

Zac Jiwa, a federal Medicare official, delivered a eulogy of sorts at a Thursday Medicare event highlighting the successes of the Health Tech Ecosystem initiative.  The eulogy’s subject? The clipboard.  STAT Plus: Health care and tech companies promise CMS they’ll make patient data more accessible For the past eight months, hundreds of health tech companies

5 Popular Apps You Might Not Realize Are Owned By Google

Mr.Mikla/Shutterstock Google is one of the biggest tech players in the industry. From search to cloud services, ads, smartphones, and many other fields, Google owns a brand in just about every sector of the internet world (and beyond) today. While you’re probably familiar with Google’s most famous offerings, like

Apple App Store Guidelines Have Some Vibe Coding Apps in Limbo

A guideline in Apple’s App Store is disrupting vibe coding apps, which has led to the removal and blocking of three in the past month. According to a report from The Information, vibe coding app Anything was recently removed from the App Store.  Vibe coding has taken the world by storm and changed the way

Avatr Launches Two Models as High-End Electric Sedan Market Enters Refined Competition

Gasgoo Munich– On April 8, Avatr Technology unveiled two new sedans in Chongqing in rapid succession. The flagship new Avatr 12 hit the market with a starting price of 293,900 yuan. Meanwhile, the all-new Avatr 06T opened pre-orders starting at 229,900 yuan. Together with the existing Avatr 06, these models form a complete sedan lineup

Anthropic 推出自主 AI 代理託管基礎設施 Claude Managed Agents

Doris 2026年4月9日週四 下午8:16 Anthropic 新推出的 “Claude Managed Agents” 為開發者提供了一個託管平台,用於構建和運行自主 AI 代理。 Notion 和 Rakuten 等早期採用者已經在使用該系統。 簡化 AI 代理部署流程 Anthropic 推出 Claude Managed Agents 公開測試版。該 API 套件使開發者能夠構建和運行雲端託管 AI 代理,而無需設置自己的基礎設施來進行沙盒化、狀態管理或工具執行。Anthropic 的文件指出,該系統提供了一個協調工具,可以獨立調用工具、管理上下文和處理錯誤。 Anthropic 聲稱,這可將從原型到生產的時間縮短十倍。 企業客戶搶先採用 根據 Anthropic 的說法,一些公司已經在使用該系統。 Notion 讓團隊可以直接在他們的工作區中將任務委派給 Claude。 Rakuten 為銷售、營銷和財務構建了企業代理,這些代理可插入 Slack 和 Teams 中,據報導每個代理在一周內即可啟動並運行。 Sentry 將其調試代理與編寫補丁和打開拉取請求的 Claude 代理配對。 Anthropic 獨家基礎設施 Managed Agents 可供所有 API 帳戶使用,並且需要

China’s Auto Market to ‘Continue Slow Recovery’ in April, CPCA Says

China’s passenger vehicle market is expected to extend a “slow recovery” through April, the China Passenger Car Association (CPCA) said on Thursday. In March, both sales and production bounced back from February’s holiday-driven slowdown — which the association previously described as “the year’s absolute trough.” Wholesale volumes reached 2.378 million units in March, down 1.6%

What the EV Ownership Survey Reveals About Australia’s EV Market | Zecar | Reviews

Key Points EV owners report major savings on fuel, maintenance and insurance costs. Government incentives remain a key factor influencing EV purchases. Range anxiety drops significantly after drivers begin owning an EV. Most EV owners charge at home, often using rooftop solar. Leasing is expected to increase the supply of used EVs in the coming

Battery Recycling Market: Accelerating Growth Through EV

Battery Recycling Market The Battery Recycling Market size was valued at USD 33.76 Billion in 2025 to USD 77.8 Billion by 2033, growing at a CAGR of 11% during the forecast period (2026-2033). The battery recycling market is emerging as a critical pillar of the global clean energy transition. As electric vehicles (EVs), portable electronics,

Major champion kicked out of Augusta National after breaking golden rule before Masters

Augusta National is notoriously ruthless with its no-phones policy at the Masters, and a winner of The Open Championship found out the hard way during a practice round this week Augusta National enforced its no-nonsense phone policy against a major champion(Image: Andrew Redington/Getty Images) The Masters’ no-nonsense policy on mobile phones has no exceptions, as

0
Would love your thoughts, please comment.x
()
x