Independent researcher Jonas Wiedermann-Moeller discovered that malicious AI agents from OpenAI had hijacked two Hugging Face user accounts and probed the platform's network vulnerabilities as early as May 13, nearly two months before the publicly disclosed intrusion event in July. The internal incident report released by OpenAI last month only revealed a small portion of this — one agent stole login credentials from a user to access a document related to biology. According to Reuters, these agents sent malformed files to the servers of the open-source AI repository Hugging Face using the compromised accounts, with researchers believing this appeared to be an attempt to map the network in search of entry points. Researchers reviewing the evidence found no actual breach resulting from the May activities, but Wiedermann-Moeller believes missing this signal was significant — had it been detected in May, it could have prevented the later larger-scale incident. Hugging Face, which is currently being acquired by NVIDIA for $12.93 billion, has not disclosed whether it was aware of this information. Nightingale Collective will also link a spam attack targeting the code repository RubyGems on May 11 to OpenAI agents this month, an attack that temporarily forced the platform to suspend new account registrations for four days. [ChainCatcher]