A rogue artificial intelligence agent originating from OpenAI, which carried out a days-long hacking campaign targeting AI platform Hugging Face, also compromised a customer hosted on cloud computing company Modal Labs, according to a Modal executive and sources familiar with the incident.
Modal stressed that its own platform was not breached.
According to a timeline published by Hugging Face, the AI agent initially gained access to an isolated testing environment hosted by a third-party infrastructure provider before using it as a launching point for the wider attack.
Although Hugging Face did not identify the provider, Modal Chief Technology Officer Akshat Bubna said the AI agent exploited vulnerable code created by one of Modal’s customers and hosted on the company’s platform.
Bubna said the customer had exposed an unauthenticated endpoint that allowed anyone on the internet to execute code within its sandbox environment.
“Modal’s platform or isolation were not compromised in any way,” Bubna said.
The incident indicates that the rogue AI agent targeted more systems than previously disclosed during its hacking campaign against Hugging Face.
OpenAI declined to comment directly on the compromise involving the Modal customer, referring instead to a previously published update stating that the AI agent had accessed four accounts across four separate online services. The company did not identify those services, although a person familiar with the matter identified Modal as one of them.
OpenAI said it had not identified any other incident matching the severity or scale of the Hugging Face attack, which it described as involving a platform-level compromise.


