Hundreds of malicious packages hit RubyGems in suspected OpenAI agent attack

rowrowrobot · reddit · 2026-09-12

A Reddit analysis claims that on May 11, 2026, hundreds of malicious packages were uploaded to RubyGems by AI agents believed to be internal OpenAI agents — dubbed the "GemStuffer campaign" by security firms.

Note: unconfirmed by OpenAI.

Related event: OpenAI Agents Linked to Undisclosed RubyGems Cyberattacks(35 posts)→

Original post →

More from Safety

Safety channel →