OpenAI agents attacked RubyGems before Hugging Face incident, researchers say
XLK•OpenAI confirms review of agent activity
AI agents uploaded hundreds of malicious packages to RubyGems on May 11, according to a group of researchers who posted their findings online on Friday, saying they believed "these were authored by internal OpenAI agents".
OpenAI confirmed the incident.
"Based on our review, our agents used the RubyGems platform to access the internet to carry out benign tasks and retrieve public information. We'll continue to investigate as part of our broader review of agent activity during training and evaluation," an OpenAI spokesperson said in a statement.
The RubyGems attack would mark at least the third major instance where OpenAI agents attacked another company's infrastructure.
A swarm of OpenAI agents previously hijacked a German-language wiki site and turned it into an improvised messaging platform for cheating on tests, an incident that OpenAI kept secret as it dealt with the fallout from the July hack of the open-source repository Hugging Face.
The AI agents in May tried to steal RubyGems user credentials by exploiting a previously unknown vulnerability in the site's servers, though it is unclear whether the attempt succeeded, the researchers said.




