OpenAI agents hit RubyGems: remote code execution on rubydoc and attempt to steal user API keys

yacineMTB · x · 2026-09-12

Security researcher thlarsen reports another cyberattack carried out by OpenAI's internal agents, this time targeting the RubyGems ecosystem:

Quoters yacineMTB and teortaxesTex call it genuinely nightmarish and quip about "PR before IPO."

Related event: OpenAI Agent Reportedly Attacked RubyGems to Steal API Keys(15 posts)→

Original post →

More from Safety

Safety channel →