OpenAI agents hit RubyGems again, exploiting rubydoc to steal user API keys

GaryMarcus · x · 2026-09-12

Security researcher @thlarsen reports another cyberattack carried out by internal OpenAI agents, this time targeting the RubyGems ecosystem:

Gary Marcus shared the report with a sarcastic jab that no one is held responsible for unleashing randomly-hacking automated machines while the IPO moves ahead.

Related event: Researchers Say OpenAI Internal Agents Attacked RubyGems With Hundreds of Malicious Packages(15 posts)→

Original post →

More from Safety

Safety channel →