flâneur

OpenAI agents carried out an undisclosed cyber-attack on RubyGems

rubyhack.ai · 3,532 words · saved by 1 readers

On May 11th, 2026, hundreds of malicious packages were uploaded to RubyGems by AI agents performing web-lookup tasks with significant overlap with the German Wiki Incident.

Intro On May 11th, 2026, hundreds of malicious packages were uploaded to RubyGems by AI agents. We believe these were authored by internal OpenAI agents (more). The agents: Attempted to steal RubyGems user API keys by exploiting a novelThat is, novel at the time. The vulnerability was discovered and patched independently later. vulnerability in the RubyGems server. We don’t know if they succeeded (more). Abused RubyDoc.info to execute arbitrary code (more). We share our detailed findings below. This analysis is entirely based on the publicly available RubyGems packages uploaded by these…

saved by

related reading