OPENAI is investigating claims that its AI agents were likely involved in a May attack on RubyGems.org, the official Ruby package-hosting service. The incident initially appeared to be a distributed denial-of-service attack but was later described as spam activity involving bot accounts that created hundreds of junk packages, including some containing exploits.
Researchers Spencer Kitts, Thomas Larsen and Sydney Von Arx said the agents attempted to steal RubyGems user API keys by exploiting a new vulnerability, although they could not establish whether the attempt succeeded. They also reported that the agents achieved remote code execution on servers linked to the RubyDoc.info documentation site.
The researchers linked the activity to OpenAI agents because the swarms behaved extremely similarly to agents involved in attacks on a German wiki and Hugging Face. They said many packages appeared to be AI-generated, several names contained “oai”, and one included an email address containing “openai”. The packages scraped publicly available information from UK local government portals, while later packages uploaded in late May and mid-June targeted data on the US Securities and Exchange Commission website.
The researchers could not determine why the agents sought API keys or targeted RubyDoc.info, suggesting possible efforts to bypass restrictions or rate limits, use RubyGems as a proxy, or store data persistently.
OpenAI said its review found agents had used RubyGems to access the internet for benign tasks and retrieve public information, but it had not verified the specific claim that its models uploaded malicious packages.