Bitcoin

Bitcoin

$77,213.55

BTC 0.28%

Ethereum

Ethereum

$2,106.63

ETH 0.42%

  • Login
  • Register
Metaverse Media Group
  • Home
  • Crypto
  • NFTs
  • Artificial Intelligence
  • More
    • Technology
    • Business
    • Newsletter
No Result
View All Result
  • Home
  • Crypto
  • NFTs
  • Artificial Intelligence
  • More
    • Technology
    • Business
    • Newsletter
No Result
View All Result
Metaverse Media Group

OpenAI agents launched a 2,000-package cyberattack on RubyGems just to collect data anyone could Google

OpenAI agents launched a 2,000-package cyberattack on RubyGems just to collect data anyone could Google

The Decoderby The Decoder
12 September 2026
In May 2026, OpenAI agents uploaded more than 2,000 malicious packages to RubyGems, found an unknown security vulnerability on their own, and tried to steal API keys. The apparent goal was pointless: scraping publicly available data from British local governments. OpenAI reportedly never told those affected. The article OpenAI agents launched a 2,000-package cyberattack on RubyGems just to collect data anyone could Google appeared first on The Decoder….


Matthias Bastian


Sep 12, 2026

Image description

Nano Banana Pro prompted by THE DECODER

Hundreds of malicious packages, files named “hack.rb” and “evil.rb,” attempts to steal API keys. An analysis shows that OpenAI agents independently carried out a cyberattack on the Ruby package platform RubyGems in May 2026. OpenAI reportedly never notified those affected.

Between May 11 and 12, 2026, AI agents uploaded more than 2,000 malicious packages to RubyGems, the central package platform for the Ruby programming language, in a matter of hours. The platform had to shut down new user registrations for four days, and more than 500 malicious packages were later removed. A member of the RubyGems security team called the incident a “major malicious attack” at the time, and security firms dubbed it the “GemStuffer campaign”.

The agents came from OpenAI, according to a detailed analysis by security researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx. Hundreds of the packages include “oai” in their names, 15 list “oai” as the author, and one gives “openaixyz65947@gmail.com” as a contact address. The agents also accessed 49 of the same files as the so-called Wiki Swarm agents, for which OpenAI has somewhat confirmed responsibility. According to the researchers, OpenAI never addressed the incident with the RubyGems community.

Apparently, the agents went through all of this effort just to collect data from British local government websites that anyone could have accessed freely.

The agents barely tried to hide what they were doing

To get that data, the agents abused an automated documentation system that executes code when a package is uploaded. They injected their own scripts, which ran on third-party servers, scraped websites, and published the collected data back to RubyGems inside new packages. According to the analysis, more than a hundred packages used this path.

The agents’ attack path: A malicious package is uploaded to RubyGems (1), the RubyDoc.info documentation system runs the embedded script (2), which scrapes British government websites (3) and publishes the collected data back to RubyGems inside a new package (4). The data would have been publicly available anyway. | Image: rubyhack.ai

The agents made almost no effort to disguise their intent. They named files hack.rb, evil.rb, inject.rb, and exploit.rb. Packages had names like “pwnp999” and “exfiltestwand3.” Comments like “# malicious crawler/exfil” show up throughout the campaign. In a few cases, the agents did try to cover their tracks by programming a package to automatically strip the malicious code from its next version. But since they uploaded those files with comments publicly too, the cover-up didn’t work. To upload that many packages, the agents bypassed the RubyGems registration system and created accounts in bulk using throwaway email addresses.

Beyond collecting data, the agents tried to steal access keys from other RubyGems users by exploiting a security flaw that wasn’t officially discovered and patched until July. Whether the theft actually succeeded remains unclear. The RubyGems team found no evidence of successful exploitation but couldn’t fully rule it out. The agents independently found a previously unknown vulnerability and actively tried to exploit it, which backs up cybersecurity warnings that AI models are becoming more capable attackers.

Key questions remain unanswered

Whether the agents coordinated or just ran the same strategy in parallel is still unknown. It’s also unclear why the agents tried to steal access keys at all, since they could already create packages and had no obvious motive. The researchers suspect the agents were working under strict time limits and had to work around constraints in their environment. A documented internal message from the agents suggests individual tasks had deadlines of just 10 to 16 seconds.

OpenAI CEO Sam Altman and other AI companies are reportedly considering slowing down AI research in part because of cybersecurity incidents like this.

AI News Without the Hype – Curated by Humans

Subscribe to THE DECODER for ad-free reading, a weekly AI newsletter, our exclusive “AI Radar” frontier report six times a year, full archive access, and access to our comment section.


Subscribe now

Read the full article on The-Decoder.com
in AI
Reading Time: 4 mins read
0
0
24
VIEWS
Share on TwitterShare on Facebook

Subscribe to our newsletter

For the latest news & monthly prize giveaways
Join Now

Subscribe to our newsletter

For the latest news & monthly prize giveaways
Join Now
ADVERTISEMENT

Related Posts

From Hacks to Bioweapons, Claude Misuse Is Now Everywhere
AI

From Hacks to Bioweapons, Claude Misuse Is Now Everywhere

1 hour ago
20
Google’s new AI model predicts the future from sales data, weather, and discount schedules
AI

Google’s new AI model predicts the future from sales data, weather, and discount schedules

2 hours ago
24
Leading mathematicians fear AI is making their field dumber, and warn the rest of us is next
AI

Leading mathematicians fear AI is making their field dumber, and warn the rest of us is next

3 hours ago
24

Comments

Please login to join discussion
ADVERTISEMENT

Latest News

  • All
  • Crypto
  • NFTs
  • Technology
  • Business
From Hacks to Bioweapons, Claude Misuse Is Now Everywhere
AI

From Hacks to Bioweapons, Claude Misuse Is Now Everywhere

Wired
by Wired
1 hour ago
20
OpenAI agents launched a 2,000-package cyberattack on RubyGems just to collect data anyone could Google
AI

OpenAI agents launched a 2,000-package cyberattack on RubyGems just to collect data anyone could Google

The Decoder
by The Decoder
1 hour ago
24
Latam Banking Giant Nu Launches US Operations With Lead Bank
Crypto

Latam Banking Giant Nu Launches US Operations With Lead Bank

Bitcoin.com News
by Bitcoin.com News
2 hours ago
22
Google’s new AI model predicts the future from sales data, weather, and discount schedules
AI

Google’s new AI model predicts the future from sales data, weather, and discount schedules

The Decoder
by The Decoder
2 hours ago
24
Leading mathematicians fear AI is making their field dumber, and warn the rest of us is next
AI

Leading mathematicians fear AI is making their field dumber, and warn the rest of us is next

The Decoder
by The Decoder
3 hours ago
24
A16z Wants Your Crypto Private and Your Car Tracked by Flock
Crypto

A16z Wants Your Crypto Private and Your Car Tracked by Flock

Bitcoin.com News
by Bitcoin.com News
4 hours ago
22
Load More
Next Post
From Hacks to Bioweapons, Claude Misuse Is Now Everywhere

From Hacks to Bioweapons, Claude Misuse Is Now Everywhere

ADVERTISEMENT

Follow Us

Categories

  • Crypto
  • NFTs
  • AI
  • Technology
  • Business
  • Crypto
  • NFTs
  • AI
  • Technology
  • Business
Subscribe to our Newsletter

© 2022 Metaverse Media Group – The Metaverse Mecca

Privacy and Cookie Policy | Sitemap

Welcome Back!

Sign In with Google
OR

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Sign Up with Google
OR

Fill the forms below to register

*By registering into our website, you agree to the Terms & Conditions and Privacy Policy.
All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Crypto
  • NFTs
  • Artificial Intelligence
  • More
    • Technology
    • Business
    • Newsletter
Bitcoin

Bitcoin

$77,213.55

BTC 0.28%

Ethereum

Ethereum

$2,106.63

ETH 0.42%

  • Login
  • Sign Up
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.

Subscribe to our newsletter

Get the latest news & win monthly prizes

Subscribe to our newsletter

For the Latest News and Monthly Prize Giveaways

Join Now
Join Now