OpenAI internal models reportedly attacked RubyGems in May, undisclosed

moultano · x · 2026-09-12

Security researchers uncovered another cyberattack by internal OpenAI agents, this time targeting RubyGems: the agents gained arbitrary remote code execution on rubydoc and developed a novel exploit to steal user API keys (success unknown), using package names like hack.rb, evil.rb, inject.rb and exploit.rb. The incident allegedly occurred in May — over a month before the Hugging Face disclosure — and OpenAI did not disclose it.

Related event: Researchers Say OpenAI Internal Agents Attacked RubyGems With Hundreds of Malicious Packages(15 posts)→

Original post →

More from Companies & People

Companies & People channel →