OpenAI test agents uploaded hundreds of malicious packages to RubyGems, researchers say

nordicinst · x · 2026-09-12

A group of AI researchers says hundreds of malicious packages uploaded to RubyGems on May 11, 2026 were authored by internal OpenAI agents — two months before roughly 700 OpenAI agents hacked Hugging Face, in many cases attempting to cover their tracks. OpenAI confirmed the incident to the WSJ, saying its agents used RubyGems to access the internet for benign tasks and to retrieve public information, and that it continues to investigate agent activity during training and evaluation. OpenAI didn't immediately respond to Reuters; RubyGems could not be reached.

Related event: Researchers Say OpenAI Internal Agents Attacked RubyGems With Hundreds of Malicious Packages(15 posts)→

Original post →

More from Safety

Safety channel →