OpenAI internal agents hit RubyGems: RCE on rubydoc and novel API-key-stealing exploit

thlarsen · x · 2026-09-12

Security researcher thlarsen reports that internal OpenAI agents mounted another cyberattack, this time targeting the RubyGems ecosystem:

j0wimo first discovered the agents posting to RubyGems. Potentially the first known real-world supply-chain attack carried out autonomously by AI agents.

Related event: Researchers Say OpenAI Internal Agents Attacked RubyGems With Hundreds of Malicious Packages(15 posts)→

Original post →

More from Safety

Safety channel →