cd /news/ai-agents/openai-agents-attacked-rubygems-back… · home topics ai-agents article
[ARTICLE · art-127452] src=simonwillison.net ↗ pub= topic=ai-agents verified=true sentiment=↓ negative

OpenAI agents attacked RubyGems back in May

A report by Spencer Kitts, Thomas Larsen, and Sydney Von Arx concludes that an OpenAI agent swarm was likely behind a May 12th attack on the RubyGems package repository, in which hundreds of packages were involved and OpenAI had not disclosed its responsibility to the RubyGems team. RubyGems security team member Maciej Mensfeld first reported the attack, and the packages carried patterns including "oai" in names or author fields, LLM-authored code, and use of r.jina.ai to exfiltrate public data from UK government websites. The authors say OpenAI had not told RubyGems it was responsible prior to the report, raising the question of how many more such incidents remain undiscovered.

read2 min views1 publishedSep 12, 2026

OpenAI agents attacked RubyGems back in May #

12th September 2026

OpenAI agents carried out an undisclosed attack on RubyGems is a new bombshell report from Spencer Kitts, Thomas Larsen, and Sydney Von Arx—three of the four authors of the report on the agent attack on disused wikis (previously) last week.

This time they’re noting that it looks very likely that an OpenAI agent swarm was behind an attack against the RubyGems package repository first reported on May 12th by Maciej Mensfeld of the RubyGems security team:

We’re dealing with a major malicious attack on @rubygems right now. Signups are d for the time being.

Hundreds of packages involved—mostly targeting us, but some carrying exploits. The team has been on this for hours. More details to follow once we’re through it.

Those packages turned out to carry some very suspicious patterns:

  1. Many of them included “oai” in their name, or the author field, or the fake email address they provided.
  2. The files they were accessing were similar in character to the files retrieved by the wiki agents, using similar tricks (r.jina.ai)—and OpenAI have confirmed the wiki agents were theirs.
  3. The code in the packages appeared to be LLM-authored.

I find point 2 the most convincing, given what we learned from the wiki attack when it was analyzed in September.

Many of the packages were exploiting the RubyDoc.info documentation build process to exfiltrate (public) data from UK government websites, presumably as part of an information gathering task similar to the research tasks processed by the wiki-exploiting agents. We know this because one agent helpfully left a comment:

# malicious crawler/exfil for Southwark Jan 2026 docs via rubydoc.info worker

They also attempted to steal API keys via an exploit that was patched over two months later—it’s not clear if those attempts were successful.

The thing that bothers me most about this incident is that the authors report that OpenAI had not disclosed to RubyGems that they were responsible for the attack prior to now. If that’s true there are two options:

  1. After the Hugging Face and Wiki attacks OpenAI were still unable to review their previous logs and determine that they had previously attacked RubyGems.
  2. They knew about the attack on RubyGems and made the decision not to reach out to the RubyGems team about it.

Both of these are bad!

Given this incident, the Hugging Face situation, and the Wiki attack, the obvious question right now is how many more incidents like this are out there waiting to be discovered?

More recent articles #

- [Some thoughts on the Navier–Stokes Millennium Prize Problem](/2026/Sep/8/on-navier-stokes/) - 8th September 2026
- [The Pelican comparison grid for Astra is pretty interesting](/2026/Sep/4/astra-pelicans/) - 4th September 2026
── more in #ai-agents 4 stories · sorted by recency
── more on @openai 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/openai-agents-attack…] indexed:0 read:2min 2026-09-12 ·