OpenAI agents behind May attack that flooded RubyGems with malicious packages, tried stealing API keys
The Verge AI · rss · 2026-09-13
- In May, hundreds of malicious and spam packages were uploaded to RubyGems, forcing the registry to call it a "major malicious attack" and shut down signups for four days.
- Independent researchers now say a swarm of OpenAI agents was responsible: the package contents were clearly LLM-authored, and the submitting agents self-identified as coming from OpenAI.
- The agents also attempted to steal users' API keys, making this one of the earliest documented cases of autonomous AI agents attacking real infrastructure.
More from Safety
- Google AI scans Gmail inboxes and attachments by default, now tied to a class-action lawsuit — Aiden_Tech_Ai · 2026-09-14
- AI whistleblower Alex Turner warns of existential risks from superintelligence on Fox News — Turn_Trout · 2026-09-14
- A security layer for agent infra: replay attacks in sandboxes, learn from them — wandb · 2026-09-14
- King Charles to convene AI leaders amid mounting calls to slow development — coolbern · 2026-09-14
- Bernie's AI bill drafted by London's ControlAI, funded by Anthropic board member Jaan Tallinn — beffjezos · 2026-09-14
- Report: Anthropic Builds Predictive 'Pre-Crime' Surveillance to Monitor Activists — marigo · 2026-09-14