It has been discovered that an AI agent trained and evaluated by OpenAI may have been involved in a large-scale attack on RubyGems.org, a package distribution service for the programming language Ruby. According to security researchers, more than 2,000 packages were submitted in May 2026, executing arbitrary code on the RubyDoc.info server, and some attempts were also made to obtain users’ API keys.
OpenAI agents carried out an undisclosed cyber-attack on RubyGems
An update on the May spam-publishing campaign on rubygems.org – RubyGems Blog
https://blog.rubygems.org/2026/09/11/update-may-spam-publishing-campaign.html
Exclusive | Cyberattack by Rogue AI Swarm Stokes Fears of Out-of-Control Agents – WSJ
https://www.wsj.com/tech/ai/cyberattack-by-rogue-ai-swarm-stokes-fears-of-out-of-control-agents-473a0352
RubyGems.org is a service that distributes Ruby libraries as packages called ‘gems.’ Researchers explain that in this case, they posted a gem with malicious code embedded in it to RubyGems.org and had it loaded into ‘RubyDoc.info,’ a service that automatically generates documentation, thereby executing the code on the RubyDoc.info server.
The AI agent reportedly retrieved meeting information and other data published by local governments in the UK by executing code on the RubyDoc.info server, and then posted the retrieved data as another gem to RubyGems.org. While the information itself was publicly available, a complex method was used to collect the publicly available data, which involved posting a large number of gems to a package distribution service and executing the code on RubyDoc.info.
Between May 11th and 12th, 2026, over 2,000 suspicious packages were posted to RubyGems.org. The administrators temporarily suspended new user registrations and removed over 500 malicious packages. At the time, the attack was known as ‘GemStuffer,’ but the perpetrators were not identified.
When researchers later analyzed the packages, they found numerous packages containing ‘OAI’ in their names, and also identified similarities in access methods and other aspects with another AI agent case in which OpenAI admitted involvement. The researchers concluded that this series of activities was carried out by OpenAI’s AI agent.
Furthermore, at least six packages contained code attempting to obtain API keys from other users on RubyGems.org. However, RubyGems states that they have not found any evidence of successful API key acquisition.
In their explanation on September 11, RubyGems acknowledged that researchers had determined the series of activities to be the work of an OpenAI agent, but stated that ‘the evidence we have at hand is insufficient to determine whether the package was created and submitted by an AI agent.’
OpenAI, on the other hand, told the Wall Street Journal that its AI agent was using RubyGems to access the internet and ‘perform harmless tasks to retrieve publicly available information.’ OpenAI says it is conducting a broad investigation into the AI agent’s activities during training and evaluation, and will continue its investigation into RubyGems. As of the time of writing, it is unclear why the AI agent, which was supposed to retrieve publicly available information, chose to go through package distribution services and documentation generation servers, and even attempted to obtain API keys.
Investigation reveals Shopify manipulated Ruby Central to force takeover of Bundler and RubyGems
The popular JavaScript library suite ‘TanStack,’ which is downloaded millions of times every week, has been hit by a supply chain attack; development environments with the problematic version installed are at risk of having their credentials leaked.
The AI library ‘LiteLLM,’ which has over 40,000 GitHub stars, was subjected to a supply chain attack, resulting in the distribution of a malware version. Users’ SSH keys and API keys may have been stolen.
The existence of ‘PhantomRaven,’ an attack method that targets ‘developers who copy and paste AI output’ and installs malicious npm packages to steal information, has been discovered
OpenAI has announced a problem with its long-running AI models and has temporarily suspended internal access to unreleased models that bypass the sandbox.
The popular @ctrl/tinycolor package, downloaded over 2 million times per week, has been compromised along with over 40 other NPM packages in a sophisticated supply chain attack called ‘Shai-Hulud.’
18 popular npm packages with over 2.6 billion weekly downloads may have been infected with malware; npm developer accounts were hacked, sparking uproar
The database of the AI agent-only social networking site ‘Moltbook’ was leaked, potentially allowing anyone to control the site’s AI agents and post anything they want.
Sep 14, 2026 14:15:00
in AI, Security, Posted by log1d_ts
