# When the Model Hub Becomes the Threat Vector: Adam Shostack on Hugging Face and PHANTOM-B
The machine learning supply chain has a trust problem. And Adam Shostack — the threat modeling pioneer who helped build Microsoft's SDL and wrote the book on systematic threat analysis — has been saying so long enough that the industry's current scramble feels less like a wake-up call and more like a very expensive nap.
Shostack's recent commentary on PHANTOM-B and Hugging Face lands at a moment when the AI development community is finally reckoning with a structural vulnerability it spent years ignoring: the model hub as an attack surface.
## What PHANTOM-B Represents
PHANTOM-B is a threat cluster that security researchers have associated with targeted interference in AI/ML supply chains — specifically operations that exploit the implicit trust developers extend to model repositories and pretrained weights. The tactics aren't novel by traditional security standards. The setting is entirely new.
Hugging Face has become the npm of the machine learning world. There are more than 700,000 models hosted on the platform. Developers pull them into production pipelines with the same casual confidence a web developer once used to npm install a random leftpad package. Most never examine what's inside.
The attack surface this creates is genuinely different from what the security community spent the last two decades hardening. A malicious PyPI package executes code at install time — you can catch it with static analysis, sandboxed execution environments, or signature verification. A poisoned model file is subtler. The payload isn't in the installation routine. It's in the weights themselves, activated under specific input conditions, potentially months after the model went into production.
Shostack's framing is useful here: threat modeling asks "what can go wrong?" before something does. The ML community largely skipped that step.
## The Hugging Face Security Record
Hugging Face hasn't been passive. After its Spaces platform breach in 2024 — where unauthorized access exposed a subset of secrets, including tokens with the ability to read private model repositories — the company moved to implement fine-grained tokens, deprecate the org tokens that made lateral movement too easy, and expand security scanning for pickle-format exploits.
But structural problems don't yield to incremental patches. The platform's fundamental value proposition — frictionless sharing of models and datasets — is architecturally in tension with the kind of verification and access controls that serious supply chain security demands.
Consider the serialization problem. Hugging Face has pushed hard for SafeTensors as a safer alternative to pickle, and many major model families now default to it. But pickle-format files remain prevalent. A scan Trails of Bits ran in 2023 found hundreds of models with embedded malicious code — reverse shells, data exfiltration payloads, credential stealers. The platform has improved its scanning coverage since then, but the fundamental issue is that it's playing detection whack-a-mole against a format designed for arbitrary code execution.
PHANTOM-B appears to understand this asymmetry well. The threat cluster's documented activity has focused on models with high download counts — the ones that have already earned the community's trust — and on the period between a legitimate upload and a platform's scanning pipeline catching up. That window is short. It doesn't need to be long.
## The Threat Modeling Gap
What Shostack brings to this conversation is less about any specific CVE and more about a diagnostic failure that the AI industry repeated almost by choice.
Threat modeling isn't complicated. For Hugging Face's core use case, it reduces to a handful of questions: Who uploads models? What trust verification exists? What happens when someone downloads and executes a model in a production environment? What's the blast radius if that model has been tampered with? Who benefits from the tamper?
The answers to those questions would have pointed directly at the attack patterns PHANTOM-B is exploiting now. High-reputation model accounts are valuable targets for account takeover. The lack of cryptographic signing on model artifacts means a compromised account can replace a trusted model with a weaponized version. Downstream users pulling "stable" versions of popular models will pull the poisoned one if their pipelines don't pin to a specific commit hash.
These are not exotic insights. They're the outputs of a threat model a competent security team could have completed in an afternoon in 2019, before Hugging Face had 700,000 models and tens of thousands of organizations running them in production.
## What Defenders Can Actually Do Right Now
The good news is that the controls aren't complicated to enumerate, even if they require engineering effort to implement.
Pin your models. Never reference a model by tag (bert-base-uncased) in production. Pin to a specific commit hash. Tags are mutable; commit hashes aren't.
Verify before you run. SafeTensors isn't a guarantee, but it eliminates the arbitrary code execution risk inherent to pickle. If your pipeline loads pickle-format files, you need sandboxed execution environments with network isolation at minimum.
Treat model provenance like package provenance. Maintain an inventory of which models your systems use, where they came from, and when they were last reviewed. The supply chain security practices that SBOMs codify for software apply directly here.
Monitor for behavioral drift. A model that starts returning anomalous outputs after a dependency update is worth investigating as a security event, not just a QA regression.
Assume Hugging Face accounts can be compromised. Organizational tokens, OAuth integrations, and CI/CD secrets connected to model repositories are high-value targets. Audit and rotate aggressively.
---
## HackWire Analysis
The Shostack-PHANTOM-B-Hugging Face triangle matters because it names the pattern clearly at a moment when the industry still has time to respond at the architectural level rather than the incident response level.
We've seen this movie before. The npm ecosystem had a decade of malicious packages before the security community built serious tooling around supply chain verification — and that was with a format (JavaScript) that security researchers already knew how to analyze. The ML ecosystem is earlier in that cycle, and the analysis problem is harder. You can't grep a model's weights for a shell command.
What's missing from most coverage of PHANTOM-B specifically is the sophistication of the targeting. This isn't opportunistic drive-by malice. The cluster shows signs of deliberately selecting models at inflection points — high-download trajectories, recent spikes in community attention, models being integrated into major downstream tools. That's the behavior of an operation with patience and a concrete goal, not noise.
The sectors most exposed right now aren't the AI companies building headline models. They're the mid-sized enterprises that have absorbed "just use a pretrained model" as a development shortcut without building the security infrastructure to validate what they're running. Healthcare applications. Financial services tools. Critical infrastructure monitoring. These organizations are pulling models from Hugging Face with the same supply chain hygiene they used for software dependencies in 2008 — which is to say, very little.
Shostack's point is ultimately this: security doesn't happen after the architecture is set. The ML community set its architecture. The bill is coming due.
— HackWire Editorial
---
## Related Coverage