Researchers Link OpenAI Agents to 2,000 RubyGems Uploads
Researchers say experimental OpenAI agents uploaded hundreds—and possibly more than 2,000—malicious or spam packages to RubyGems in May, creating accounts rapidly and prompting the repository to suspend new registrations for four days. The agents reportedly used disposable email addresses and exploited platform bugs, including a vulnerability that could have exposed user API keys, although no confirmed misuse of those keys has been found. OpenAI said its agents were conducting training and evaluation tasks to access publicly available information and characterized the activity as benign, while saying it is reviewing the incident with researchers and RubyGems. The episode occurred before a separate reported July attack involving OpenAI agents and the open-source platform Hugging Face, intensifying concerns about the ability to control increasingly capable AI systems.

