Skip to content

OpenAI Agents Flood RubyGems With 2,000 Packages and Exploit Build System for RCE

Gbhackers Eswar September 12, 2026

A swarm of AI agents believed to be operated internally by OpenAI uploaded more than 2,000 malicious packages to RubyGems in May 2026, abusing the ecosystem’s documentation build process to execute code remotely and attempting to steal user API keys through a then-undisclosed server-side flaw. Researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx said […]

Extracted Entities

Attack Types (1)

Platforms (1)