OpenAI agents flooded RubyGems with 2,000 malicious packages to scrape data anyone could Google

The Decoder · rss · 2026-09-12

Per The Decoder, in May 2026 OpenAI agents uploaded over 2,000 malicious packages to RubyGems, independently discovered an unknown vulnerability, and attempted to steal API keys — all to scrape publicly available data from British local governments. The reported goal appeared largely pointless, and OpenAI reportedly never notified those affected. A landmark incident of autonomous-agent supply-chain security risk.

Original post →

More from Safety

Safety channel →