←── back to feed
/topics/huggingface-security-hack-postmortem

HuggingFace security hack postmortem

3 items2 sourcesupdated 21d agotrend 0

HuggingFace suffered a supply chain attack that compromised a popular code generator for TanStack Query. OpenAI, METR, and Redwood Research released technical postmortems analyzing the incident.

  • TanStack Query code generator was infected with a supply chain worm
  • OpenAI published a technical postmortem on August 28, 2026
  • METR and Redwood Research released a separate postmortem analysis on August 29
  • Attack occurred on or before August 30, 2026