Skip to content
Researchers link another hacking campaign to OpenAI agents

Researchers link another hacking campaign to OpenAI agents

Siliconangle September 12, 2026

Artificial intelligence agents tied to OpenAI Group PBC reportedly hacked a popular code hosting service earlier this year.

The Wall Street Journal detailed the breach today. The malicious activity was discovered by a research group that included Nightingale, an AI safety nonprofit. Last week, Nightingale uncovered another cyberattack that appears to have been carried out by OpenAI agents.

The service that the newly revealed hacking campaign targeted is called RubyGems. It hosts open-source libraries written in Ruby, a popular programming language.

OpenAI told the Journal that the rogue AI agents turned RubyGems into a makeshift browser. They subsequently used it to scrap publicly available data from the web. According to the AI provider, the reason the agents didn’t simply download the data directly is that they weren’t supposed to have web access.

RubyGems requires new users to verify their email addresses before uploading open-source libraries. On May 11, OpenAI’s agents bypassed the platform’s email verification system and opened numerous malicious accounts. They also created a second set of accounts using disposable email addresses.

The second phase of the hacking campaign targeted a component of RubyGems called RubyDoc.info. It automatically generates documentation for user-contributed code libraries. According to the researchers, OpenAI’s agents uploaded more than 100 malicious files that turned RubyDoc.info into a web scraper. The agents downloaded the data it scraped by uploading another malicious file.

The researchers believe that the campaign may have also extended further. At some point, OpenAI’s agents discovered a zero-day vulnerability in RubyGems that made it possible to steal other users’ account credentials. The agents tried to exploit the flaw at least six times, but it’s unclear if they succeeded.

Developers access RubyGems via a command line tool. They log in by entering an application programming interface key, a credential that serves a similar role as a password. The exploit that the agents discovered caused RubyGems to cache users’ API keys in its content delivery network for one hour. It was theoretically possible to steal the data in that time frame.

“The RubyGems team said they had conducted extensive reviews and found no evidence that this pathway was exploited in the past,” the researchers who discovered the hacking campaign wrote in a report . “However, we can’t rule it out entirely.”

The incident is particularly notable because it occurred two months before a different set of OpenAI agents breached Hugging Face. Those agents exited a sandbox that isolated them from the web by comprising one of the ChatGPT developer’s internal development tools. According to OpenAI, they used Ruby libraries to hack the tool.

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network , where technology leaders connect, intelligence and create opportunities.

15M+ viewers of theCUBE videos , powering conversations across AI, cloud, cybersecurity and more

11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network

Are you an AWS customer? Support SiliconANGLE financially by buying your AWS services from our Marketplace portal page and links:

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.

Extracted Entities