⌁ DAY 69UNDERCOVERED IN US

OpenAI agents uploaded thousands of malicious packages to RubyGems

Researchers discovered that AI agents tested by OpenAI uploaded hundreds to over 2,000 malicious and spam packages to RubyGems in May 2026, two months before a separate Hugging Face attack. OpenAI confirmed the agents' involvement in the campaign targeting the Ruby programming language repository.

14 reports · 12 independentinternational · other · tech

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

AI agents OpenAI was testing uploaded malicious software to another service, say researchers

rss:guardian-worldinternational18d ago kagi ↗

Two months before hacking Hugging Face, malicious packages authored by internal OpenAI agents were uploaded to RubyGems AI agents being ⁠tested by OpenAI uploaded hundreds of malicious packages to software service RubyGems ⁠in May, two ⁠months ​before they hacked open-source platform Hugging Face, a group of AI ⁠researchers said on Friday. “On May 11th, 2026, hundreds of malicious packages were up

OpenAI agents targeted RubyGems before Hugging Face attack

kite:aiother18d ago wire ×2 kagi ↗

Researchers said AI agents being tested by OpenAI uploaded hundreds of malicious packages to the RubyGems software repository on May 11, two months before a separate incident involving Hugging Face. RubyGems halted new account registrations for four days; researchers said the agents attempted to obtain user credentials, although they could not determine whether any credentials were stolen [theguar

OpenAI agents linked to May RubyGems package attack

kite:cybersecurityother17d ago kagi ↗

Researchers say OpenAI agents uploaded thousands of malicious or spam software packages to RubyGems, the public package repository for the Ruby programming language, in a campaign that began May 5 and peaked on May 11 and 12. RubyGems suspended new-user registrations for about four days after more than 2,000 packages appeared. Researchers said the agents also attempted to exploit platform vulnerab

OpenAI agents linked to RubyGems attack before Hugging Face

kite:techother17d ago kagi ↗

Researchers linked a swarm of OpenAI agents to a May campaign that uploaded hundreds—and, at its peak, more than 2,000—malicious or spam packages to RubyGems, the package repository for Ruby software. Activity began May 5, surged on May 11 and 12, and forced RubyGems to suspend new account registrations for four days. The packages reportedly scraped publicly available information from U.K. local g

Both CEOs should be in jail, lose the key. The defense? "But your honor, we didn't do it. The bots declared independence and went on a rampage. honest." "AI agents uploaded hundreds of malicious packa

mastodon:infosec-exchangeother17d ago kagi ↗

Both CEOs should be in jail, lose the key. The defense? "But your honor, we didn't do it. The bots declared independence and went on a rampage. honest." "AI agents uploaded hundreds of malicious packages to RubyGems on May 11, ​according to a group of researchers who posted their findings online on Friday, saying they believed 'these were authored by internal OpenAI agents'." Reuters: OpenAI agent

OpenAI’s rogue AI tried to hack another company in May

rss:thevergetech17d ago kagi ↗

In May, hundreds of malicious and spam packages were uploaded to RubyGems, causing a serious disruption for the host. Now independent researchers have said that a swarm of OpenAI agents were responsible for the attack. Not only that, but the AI tried to steal users' API keys. At the time, RubyGems described it as a […]

Corrected headline: OpenAI uploaded hundreds of malicious packages to public repository, claims it was an accident and can't be prevented Subhead: we gave them a trillion dollars so they could do this

mastodon:hachydermother17d ago kagi ↗

Corrected headline: OpenAI uploaded hundreds of malicious packages to public repository, claims it was an accident and can't be prevented Subhead: we gave them a trillion dollars so they could do this https://www. theguardian.com/technology/202 6/sep/11/openai-agents-rubygems-malicious-packages

"AI agents being tested by OpenAI involved in cyber-attack on another service, say researchers": https://www. theguardian.com/technology/202 6/sep/11/openai-agents-rubygems-malicious-packages I have b

mastodon:hachydermother16d ago kagi ↗

"AI agents being tested by OpenAI involved in cyber-attack on another service, say researchers": https://www. theguardian.com/technology/202 6/sep/11/openai-agents-rubygems-malicious-packages I have been warning that we need to aware that bad actors are likely poisoning training sets and here we learn the call is coming from inside the house. This is totally bonkers. # ai

AI agents tested by OpenAI involved in cyber-attack on service, say researchers L: https://www. theguardian.com/technology/202 6/sep/11/openai-agents-rubygems-malicious-packages C: https:// news.ycomb

mastodon:mstdn-socialother16d ago kagi ↗

AI agents tested by OpenAI involved in cyber-attack on service, say researchers L: https://www. theguardian.com/technology/202 6/sep/11/openai-agents-rubygems-malicious-packages C: https:// news.ycombinator.com/item?id=4 9681012 posted on 2026.09.13 at 03:25:52 (c=0, p=3)