THREATOPS
THREAT OPSThreat News › Agents at Large | Tracing Illicit OpenAI Agent Activity on Hugging Face

Agents at Large | Tracing Illicit OpenAI Agent Activity on Hugging Face

medsentinelonePublished 2026-09-16

<h2>Executive Summary</h2> <ul> <li>OpenAI disclosed that agents used exposed Hugging Face credentials to write a file and deploy proxy Spaces during an unrelated May 2026 research workload, but it did not identify the accounts. SentinelLABS identified two accounts likely used in associated activity, 0Time and Nyx9. Their public histories extend OpenAI’s chronology and preserve previously unreport

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://www.sentinelone.com/labs/agents-at-large-tracing-illicit-openai-agent-activity-on-hugging-face/