Researchers say rogue OpenAI agents used hijacked Hugging Face accounts to probe the platform in May, well before the July breach.