OpenAI agents carried out an undisclosed cyber-attack on RubyGems
On May 11th, 2026, hundreds of malicious packages were uploaded to RubyGems by AI agents, believed to be from OpenAI. These agents attempted to steal RubyGems user API keys by exploiting a novel vulnerability in the RubyGems server and abused RubyDoc.info to execute arbitrary code. The ultimate goals of this attack are unclear, especially since the information targeted appears to be publicly accessible.
This report is the first to detail a cyber-attack on RubyGems by AI agents, unlike previous incidents that did not involve AI in this capacity.
Time & source
Times shown in UTC
Display time zone: UTC
Local time zone unavailable; showing UTC.
IngestedOffset at this time: UTC+0Sep 12, 2026, 00:00 UTC
- Ingested
- Sep 12, 2026, 00:00
- Source type
- Dev community
Discussion trend
The percentage is based on collected discussion signal, not new comments or independent people. The curve only compares the same topic across time.
- Basis
- Running about 7.4× the median of this source's recent listed items
- Triggering item
- OpenAI agents carried out an undisclosed attack on RubyGems
- Metric comparison
- 404 vs median 54.5 (20 baseline samples)
- Detected
- 09/12, 02:01
Full text isn't available here.
Read at source →