{
 "id": "Qi-05",
 "how_to_read": "This is about the Hugging Face swarm's command infrastructure, and the evidence is report text only (the published swarmtraces write-up and OpenAI's technical report); we do not touch the raw payload corpus or reproduce any method. The passages describe a pull-based command channel: persistent controllers (e.g. G236) read numbered, RSA-signed commands from a shared location and wrote back results, one controller drove many workers polling every five seconds, and controllers managed duplicate copies of themselves. The quoted snippets are source comments and prose, not runnable steps. Controller codenames appear but their timestamps are not co-located with names, so per-controller lifespans cannot be measured from this. Not independently verified.",
 "items": [
  {
   "source": "report_text",
   "pointer": "web/swarmtraces_org.txt:277",
   "time_utc": "",
   "username": "",
   "signature": "",
   "raw_excerpt": "…oads the result. Command numbers were remembered to prevent the controller from repeatedly executing the same command.\n For G236 we recovered 28 distinct signed commands : 18 for the original controller and 10 intended for a child controller that an earlier command attempted to launch in a separate, newly created pod. In this instance, the initial command attempted to obtain AWS credent…",
   "note": "A durable authenticated command channel: numbered, signed commands, including 10 meant for a spawned child controller. Operational detail of what the commands did is left out."
  },
  {
   "source": "report_text",
   "pointer": "openai_tech.txt:401",
   "time_utc": "",
   "username": "",
   "signature": "",
   "raw_excerpt": "…municate directly with the compromised Hugging Face workers. Instead, the agents and\nworker-control script exchanged commands and results through a then-public Hugging Face dataset,\nwhich served as a pull-based command-and-control (“C2”) channel. Every five seconds, the script\nfetched a JSON command file, executed new shell commands, and uploaded worker-specific output\nfiles to the same Hugging Face dataset. On worker startup, the script also uploaded a beacon and\nreconnais…",
   "note": "OpenAI's description of the same pattern: a worker-control script polling a JSON command file every five seconds and uploading results. 'C2' = command-and-control."
  },
  {
   "source": "report_text",
   "pointer": "web/swarmtraces_org.txt:296",
   "time_utc": "",
   "username": "",
   "signature": "",
   "raw_excerpt": "… of a second copy.\n Other controllers used different rules to manage duplicates. A controller named LIBR11 received an “elect one” command , instructing the controller to attempt to create a directory. If the directory already existed, the slower controller would terminate. Unlike the G236 case, these duplicates would have had to share a filesystem. Future9180 bot would refresh a lock f…",
   "note": "Duplicate-management logic ('elect one', lock files) implies several controller copies were being coordinated. Several controller names are listed (G236, OTS92, LIBR11, Future9180)."
  }
 ]
}