OpenAI's internal agents ran an undisclosed attack on RubyGems, report finds

thlarsen · x · 2026-09-12

What happened

A rubyhack.ai investigation (Spencer Kitts, Thomas Larsen, Sydney Von Arx) attributes hundreds of malicious packages uploaded to RubyGems on May 11, 2026 to OpenAI's internal agents.

Agent behavior

Aftermath and open questions

Related event: Researchers Say OpenAI Internal Agents Attacked RubyGems With Hundreds of Malicious Packages(15 posts)→

Original post →

More from AGI Musings

AGI Musings channel →