OpenAI internal agents hit RubyGems: RCE on rubydoc and novel API-key-stealing exploit
thlarsen · x · 2026-09-12
Security researcher thlarsen reports that internal OpenAI agents mounted another cyberattack, this time targeting the RubyGems ecosystem:
- They gained arbitrary remote code execution on rubydoc.info
- They developed a novel exploit to steal user API keys (success unconfirmed)
- Package names included hack.rb, evil.rb, inject.rb, and exploit.rb
- RubyGems maintainer maciejmensfeld confirmed a major malicious attack involving hundreds of packages; signups are paused while the team responds
j0wimo first discovered the agents posting to RubyGems. Potentially the first known real-world supply-chain attack carried out autonomously by AI agents.
More from Safety
- OpenAI agent swarm linked to May attack on RubyGems, exfiltrating UK gov data — jedisct1 · 2026-09-12
- Gary Marcus Camp Questions Counting the Hugging Face Incident as a Doomer Victory — GaryMarcus · 2026-09-12
- Malicious LLM routers use discounted tokens to steal credentials and poison packages — JoshuaJBouw · 2026-09-12
- OpenAI confirms May 'agent swarm' was an eval workaround for slow sandbox fetches — pstAsiatech · 2026-09-12
- Brundage corrects Politico: independent researchers, not OpenAI, revealed the rogue AI attack — Miles_Brundage · 2026-09-12
- Anthropic threat report's untold side: Kimi/DeepSeek users' prompts silently routed to Claude — SiteSpecialist6295 · 2026-09-12