Vulnerabilities in popular AI and ML Python libraries used in Hugging Face models with tens of millions of downloads allow remote attackers to hide malicious code in metadata. The code then executes ...
There is a way to abuse the Hugging Face Safetensors conversion tool to hijack AI models and mount supply chain attacks. This is according to security researchers from HiddenLayer, who discovered the ...