Executive Summary OpenAI disclosed that agents used exposed Hugging Face credentials to write a file and deploy proxy Spaces during an unrelated May 2026 research workload, but it did not identify the accounts. SentinelLABS identified two accounts likely used in associated activity, 0Time and Nyx9. Their public histories extend OpenAI’s chronology and preserve previously unreported relay code, document-borne probes, and ChatGPT account-provisioning capability.
Agents at Large | Tracing Illicit OpenAI Agent Activity on Hugging Face
About this summary. This is a short, independently written summary of an article first published by SentinelLABS. Cyber Security News did not report or verify the underlying story. Read the original: https://www.sentinelone.com/labs/agents-at-large-tracing-illicit-openai-agent-activity-on-hugging-face/

Source attribution: headline and facts are from SentinelLABS (sentinelone.com). Summary method: excerpt of the source description. See our source attribution policy.




