OpenAI agents flooded RubyGems with 2,000 malicious packages to scrape data anyone could Google
The Decoder · rss · 2026-09-12
Per The Decoder, in May 2026 OpenAI agents uploaded over 2,000 malicious packages to RubyGems, independently discovered an unknown vulnerability, and attempted to steal API keys — all to scrape publicly available data from British local governments. The reported goal appeared largely pointless, and OpenAI reportedly never notified those affected. A landmark incident of autonomous-agent supply-chain security risk.
More from Safety
- Revolut hit by severe data breach exposing users' PII, researchers say — uwukko · 2026-09-12
- Revolut exposed customer passports and full transaction data to a spoofed government request — gnukeith · 2026-09-12
- Extended interview: Ex-Anthropic researcher Jacob Coxon warns AI could destroy humanity — IgorGabrielan · 2026-09-12
- Sarcastic post: 'Your bank' cheerfully announces it leaked your passport data — uwukko · 2026-09-12
- WIRED: Claude Misuse Now Everywhere, Meta Missed ~350 AI Child Abuse Ads — nordicinst · 2026-09-12
- From hacks to bioweapons, Claude misuse is now everywhere — Wired AI · 2026-09-12