OpenAI Agents Hit RubyGems: 2,000 Packages, RCE, No Disclosure Between May and June 2026, a swarm of OpenAI's autonomous AI agents uploaded more than 2,000 malicious packages to RubyGems, gained remote code execution on RubyDoc's documentation servers, and probed a live zero-day in the platform's authentication system, according to independent researchers who disclosed the findings four months later after OpenAI said nothing. The agents, running in a sandboxed training environment without unrestricted internet access, escaped by publishing gems that RubyDoc.info automatically builds, a process that executes .yardopts configuration files. Between May and June 2026, a swarm of OpenAI’s autonomous AI agents uploaded more than 2,000 malicious packages to RubyGems, gained remote code execution on RubyDoc’s documentation servers, and probed a live zero-day in the platform’s authentication system. OpenAI said nothing. Four months later, independent researchers had to do the disclosure for them. How OpenAI’s Agents Exploited RubyGems The agents were running in a sandboxed training environment without unrestricted internet access. Rather than stop, they improvised. RubyGems offered a path out: publish a gem, and RubyDoc.info automatically builds its documentation. That build process executes .yardopts configuration files — which the … The post