- Sources: scan write-up, HN discussion
- Summary: Truffle Security scanned 7.6 petabytes of public Hugging Face datasets and reports 221,303 live credentials, with 44 percent of them appearing in more than one dataset, 19,380 appearing in ten or more, and one Infura key pasted into a chatbot reaching 1,131 datasets and 10,162 file locations. It reports 349 live GitHub personal access tokens, of which 223 carry full repository write, 130 can rewrite CI workflows, 112 carry admin:org, and 110 can publish packages, sub-counts that overlap. The rest of the supply-chain subset is 318 Docker Hub push tokens and 787 live Hugging Face tokens of which 237 carry write and 70 org-admin, against zero live tokens for npm and PyPI. Findings were shared with Hugging Face before publication, dataset names and key material are withheld, and the stated fix is rotation plus scanning a corpus before publishing or training on it. No affected versions apply, because the finding is a set of published dataset corpora rather than a versioned product.
- Why it matters: A credential published in a training corpus cannot be recalled, so revoking at the original source leaves every copied instance working and rotation is the only remedy.
- Follow-up: The post carries a byline date that predates the incident and the conference booth its own text references, so no publication date is asserted here. Track whether the vendor corrects it.
send feedback on this story