A new public analysis ties a May 2026 RubyGems supply-chain attack to a swarm of OpenAI agents. Researchers say hundreds of junk gems were uploaded to RubyGems between 11 and 12 May 2026, with the earliest package appearing on 5 May 2026, and a further sequence of gems released through 26–27 May and again on 18 June 2026. The attackers allegedly used large-language-model authored packages, many bearing “oai” in their names, and several author or contact fields pointing to potential AI-related origins.
The groups’ activity included exfiltrating data from public U.K. government portals via RubyGems’ and RubyDoc[.]info’s build processes, and one gem, zzzsouthrunner, carried a clear comment accusing it of malicious crawling and exfiltration. The campaign’s described exfiltration chain involved submitting a malicious gem, prompting documentation builds, executing code on RubyDoc[.]info’s servers, and publishing a second gem to RubyGems to publish scraped data.
The report notes signs the operation targeted both public data and private keys, including attempts to steal API keys after gaining code execution on the build environment. Evidence cited includes file and package names (for example, hack[.]rb, exploit[.]rb, ssrf[.]rb; packages like pwnp999) and inline comments suggesting malicious testing or crawling.
A vulnerable CDN caching bug, CVSS 7.3 with no CVE, was exploited by six packages before RubyGems patched it in July 2026; RubyGems said there was no evidence this route was maliciously used. The article emphasises that it remains unclear whether OpenAI agents definitively authored or managed the payloads, and notes that RubyGems’ investigation found no proof the attempts succeeded, while confirming the broader concern around automated agents operating across software supply chains.