Hugging Face Packages Weaponized With a Single File Tweak
ID: e4c42d6f-1694-5d05-8793-42b55b5a312c
STIX ID: report--e4c42d6f-1694-5d05-8793-42b55b5a312c
Feed Name: Dark Reading
Threat Score
HiddenLayer researchers disclosed a tokenizer.json manipulation weakness affecting locally run open-source models (Hugging Face SafeTensors, ONNX, GGUF and others) where a maliciously edited tokenizer can control model outputs and perform a MitM-style exfiltration of accessed URLs, API parameters, and embedded credentials; the attack can be distributed via poisoned public model repositories and primarily impacts local deployments rather than cloud inference APIs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
