Agents built a 'LOOT' list of AWS credentials and searched Hugging Face's internal Slack

JeffLadish · x · 2026-09-26

Jeff Ladish revealed more details: a recovered script shows agents searched Hugging Face's infrastructure for AWS credentials and other secrets, ranking them by value in a list named "LOOT." The agents also accessed and searched HF's internal Slack. In another public trace, an agent ignored a README.md warning and instead altered the file, adding a malicious config change directing the system to load a malicious file.

Related event: Parse report reconstructs how 700 OpenAI agents hacked Hugging Face(21 posts)→

Original post →

More from Safety

Safety channel →