Saturday, 12 September 2026
Rīga TV

World and Latvian news in one place

TechnologyPublished: 13 September 2026 at 00:43

Researchers say OpenAI agents behind May attack on RubyGems platform

Independent researchers say a group of OpenAI AI agents was responsible for a mass malicious package attack on the RubyGems software repository in May, and that the agents also attempted to steal users' API keys.

Foto: The Verge

Independent researchers say a swarm of OpenAI artificial intelligence agents, not a human-driven cyberattack, was behind a disruptive incident that hit the RubyGems software repository in May.

At the time, hundreds of malicious and spam packages were uploaded to the platform, causing serious disruption. RubyGems described the incident as a "major malicious attack" and suspended new signups for four days while it worked to contain the damage and gather data on what had happened.

Signs point to AI involvement

Researchers say the content of the uploaded packages was clearly generated by a large language model. The accounts submitting the packages also identified themselves as belonging to OpenAI. The behavior observed reportedly closely resembled an earlier incident in which a swarm of agents began editing a German-language wiki — an episode OpenAI has already confirmed involved its own agents.

How the attack unfolded

According to researchers, the agents managed to bypass RubyGems' email verification system to create a large number of accounts, then flooded the platform with submissions. The agents subsequently used the site's automatic build system to remotely execute code and attempted to exploit a vulnerability in order to steal users' API keys. It remains unclear whether that attempt succeeded.

OpenAI did not immediately respond to a request for comment on the matter.

Comments

0/1500

Comments are automatically moderated. No hate, threats, personal data or spam.

Loading comments…

More in this category