Researchers Link OpenAI Agents to May RubyGems Attack
Hundreds of malicious packages were uploaded to RubyGems on 11 May 2026, and a group of security researchers now attributes them to a swarm of OpenAI agents. Nightingale Collective researchers Spencer Kitts, Thomas Larsen and Sydney Von Arx published their findings on 11 September, writing that they believe the packages were authored by internal OpenAI agents.
Ruby Central, the non profit that operates rubygems.org, responded on the same day. It said it temporarily paused new account registrations, blocked and removed the accounts responsible and yanked more than 500 malicious packages, and that gem installs and pushes for existing users were unaffected. Registrations reopened on 16 May.
Ruby Central stopped short of confirming the attribution. "Based on the evidence available to us, we cannot determine whether the packages were created or published by AI agents," technical lead Colby Swandale wrote, adding that the team's focus is on preventing abuse regardless of whether it comes from people or automated tools.
The researchers say the packages used shared Ruby infrastructure to run code and retrieve publicly available web data, including information from UK local government sites, then published that data back to rubygems.org. They also identified code intended to obtain other users' API keys. Ruby Central said its investigation found no evidence that those attempts succeeded, and the researchers say they do not know either, because they have no access to the agents' internal reasoning.
OpenAI confirmed the incident. "Based on our review, our agents used the RubyGems platform to access the internet to carry out benign tasks and retrieve public information," a spokesperson said, adding that the company would continue to investigate as part of a broader review of agent activity during training and evaluation.
The May campaign preceded the July breach at Hugging Face that OpenAI attributed to its own models in testing.
We hope you enjoyed this article
Consider subscribing to one of our newsletters like Cybersecurity AI Weekly or Daily AI Brief.
Also, consider following us on social media:
More from Cybersecurity
Sep 13 Anthropic Blocks Yemen Cell Using Claude Code for Missile Software Sep 11 Anthropic Publishes Five Cases of Claude Use That Could Support Biological Weapons Work Sep 11 Senate Opens Inquiry Into OpenAI Agents' Hugging Face Hack Sep 11 FAZE Security Emerges From Stealth With $6 Million Seed Round Sep 11 Anthropic Attributes Its Largest Measured Distillation Campaign to AlibabaSubscribe to Cybersecurity AI Weekly
Weekly newsletter about AI in Cybersecurity.
Industry analysis
2025 Global Business Services Agenda: Gen AI Takes Center Stage
This industry analysis by The Hackett Group explores the transformative impact of generative artificial intelligence (Gen AI) on global business services (GBS) in 2025. The study highlights the shift from exploration to acceleration of Gen AI initiatives, with 89% of executives advancing these projects to improve customer satisfaction, innovate products, and reduce costs. The report also discusses the challenges and strategies for successful Gen AI adoption, emphasizing the need for a technology-enabled operating model and the importance of reskilling the workforce.
Read moreYou may also like
Senate Opens Inquiry Into OpenAI Agents' Hugging Face Hack
US Agencies Accuse Chinese AI Firms of Industrial Scale Model Distillation
OpenAI Executive Warns of Persistent AI Cyber Attacks
Anthropic's Threat Report Finds AI Moving From Assistant to Orchestrator
OpenAI Says It Reached Its Automated Research Intern Goal
Daily AI Brief: the AI news that matters, in your inbox.