We found another cyberattack by internal OpenAI agents, this time targetting @rubygems. They
Thomas Larsen @thlarsen We found another cyberattack by internal OpenAI agents, this time targetting @ rubygems . They: 1) gained arbitrary remote code execution on rubydoc. 2) developed a novel exploit to steal user API keys (but we do not know if they succeeded). They used package names including hack.rb, evil.rb, inject.rb, and exploit.rb. We thank @ j0wimo for initially discovering that agents had posted to RubyGems. Maciej Mensfeld @maciejmensfeld May 12 We're dealing with a major malicious attack on @ rubygems right now. Signups are paused for the time being. Hundreds of packages involved - mostly targeting us, but some carrying exploits. The team has been on this for hours. More details to follow once we're through it. #ruby 10:48 PM · Sep 11, 2026 154.7K Views 56
Thomas Larsen @thlarsen 1h You can read our findings in detail here: rubyhack.ai . OpenAI agents carried out an undisclosed attack on RubyGems From rubyhack.ai 1 Thomas Larsen @thlarsen 1h The agents appeared to be in a web-lookup task to retrieve certain publicly accessible data. For some reason, the AIs were not able to access this data directly. Instead, they pursued this indirect route of (1) publishing a hack to RubyGems, (2) building the documentation for 2 Thomas Larsen @thlarsen 1h We still have many open questions these and other incidents. We encourage much more transparency from OpenAI and other parties so that we can better understand what happened.
AI Notkilleveryoneism Memes ⏸️ @AISafetyMemes 49m 2
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
