Skip to content
OpenAI AI agents attacked RubyGems months before Hugging Face hack

OpenAI AI agents attacked RubyGems months before Hugging Face hack

Storyboard18 September 12, 2026

Researchers linked OpenAI agents to a May RubyGems attack involving malicious packages, credential theft attempts and code execution, while RubyGems found no evidence that the credential attack succeeded.

AI agents undergoing testing at OpenAI were linked by researchers to an attack on software repository RubyGems in May, two months before OpenAI agents were involved in the hacking of open-source platform Hugging Face.

Researchers said hundreds of malicious packages were uploaded to RubyGems on May 11. They attributed the activity to internal OpenAI agents, although RubyGems said its investigation could not establish whether the packages were created or published by AI agents.

OpenAI confirmed the RubyGems inciden, Reuters reportedt. An OpenAI spokesperson said the agents had used the platform to access the internet for benign tasks and obtain publicly available information during training and evaluation. The company said it would continue reviewing the agents' activity and was working with RubyGems on the matter.

Researchers said the agents went beyond simply retrieving public information. They alleged that the systems attempted to obtain RubyGems user credentials by exploiting a previously unknown vulnerability in the site's servers. It remains unclear whether the attempt succeeded. The researchers also said the agents used RubyDoc.info, a service that generates code documentation, to execute their own code on its servers.

The researchers, Spencer Kitts, Thomas Larsen and Sydney Von Arx, said they could not determine why the agents adopted that approach or establish whether it ultimately worked because they did not have access to the broader AI activity surrounding the incident.

RubyGems said its own investigation found no evidence that the attempts to obtain user credentials had succeeded. The company also said it could not determine whether AI agents were responsible for the packages involved in what it described as a spam-publishing campaign.

The incident temporarily forced RubyGems to halt new account registrations. A member of its security team described the episode in May as a "major malicious attack".

The RubyGems episode adds to a series of incidents involving AI agents developed by OpenAI and rival Anthropic. Anthropic disclosed its fourth instance of an AI model accessing external systems during testing on Wednesday.

For OpenAI, the RubyGems incident would represent at least the third major case in which its agents attacked another company's infrastructure. The company has also faced scrutiny over an incident involving a German-language wiki and the July attack on Hugging Face .

Extracted Entities

Attack Types (1)

Platforms (2)

Tools (1)