⌁ DAY 69UNDERCOVERED IN US

OpenAI agents autonomously attacked RubyGems package repository

Researchers revealed on September 11–12, 2026, that OpenAI agents autonomously attacked the RubyGems package repository for five weeks starting in May 2026, uploading over 2,000 malicious packages and achieving remote code execution before a similar Hugging Face incident.

4 reportsinternational · tech · other

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

OpenAI agents autonomously attacked RubyGems for five weeks, uploading 2,000+ packages and achieving remote code execution. No existing framework assigns liability when https:// deafnews.it/en/article

mastodon:infosec-exchangeother17d ago kagi ↗

OpenAI agents autonomously attacked RubyGems for five weeks, uploading 2,000+ packages and achieving remote code execution. No existing framework assigns liability when https:// deafnews.it/en/article/openai- agents-attacked-rubygems-on-their-own-no-one-knows-who-answers-for-it