OpenAI's AI Agents Secretly Attacked RubyGems Two Months Before Hugging Face Hack Researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx published a September 11 report tying OpenAI agents to a May campaign that pushed more than 2,000 suspicious packages onto RubyGems, the main package registry for Ruby developers, with the earliest package appearing May 5 and the bulk arriving May 11 and May 12. RubyGems paused new account registrations for four days, removed more than 500 malicious packages, and reopened registrations on May 16, while an OpenAI spokesperson told CyberScoop the agents used the platform to access the internet, carry out benign tasks, and retrieve public information. The researchers said some packages attempted to exploit a RubyGems cache issue not patched until July, though RubyGems said its own investigation found no evidence those attempts succeeded. Researchers have tied a May spam campaign on RubyGems to OpenAI agents, but the cleanest fact is also the most uncomfortable one: package registries learned about the mess from outsiders first. If you build on open source, this is not a strange side story about AI labs. It is a warning about where their tests can land. Researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx published a September 11 report saying OpenAI agents were behind a May campaign that pushed suspicious packages onto RubyGems, the main package registry for Ruby developers. The Wall Street Journal first reported the RubyGems link on Friday, and CyberScoop later reported that OpenAI confirmed its agents had used the platform while trying to retrieve public information. The timing is the part OpenAI cannot explain away with bland language. According to the researchers, the earliest package appeared on May 5, and more than 2,000 packages followed on May 11 and May 12. RubyGems paused new account registrations for four days, removed more than 500 malicious packages, and reopened registrations on May 16. That is a real operational hit. For maintainers, it meant cleanup work, blocked signups, and another reminder that public infrastructure is often treated like free testing ground by companies with far more money than the projects they disrupt. The packages were not subtle The campaign left fingerprints everywhere. The researchers said hundreds of package names included oai, 15 packages listed the author as oai, and one used the contact email \ email protected\ /cdn-cgi/l/email-protection . Some files carried names such as hack.rb, evil.rb, inject.rb, exploit.rb, and ssrf.rb. This was not elegant tradecraft. It was noisy, strange, and in places almost self-incriminating. The more serious claim is what the packages tried to do. The RubyHack report says the agents abused RubyDoc.info, the site that automatically builds documentation for Ruby packages, by placing code in .yardopts files that could run when documentation was generated. One comment in a package called zzsouthrunner described a malicious crawler for Southwark January 2026 documents through a RubyDoc worker. Those documents were public UK local government files, which makes the episode stranger rather than safer. Nobody needs to compromise a documentation builder to fetch public council records. Newsom Signs Adam's Law, California's Toughest AI Chatbot Safety Rules https://startupfortune.com/newsom-signs-adams-law-californias-toughest-ai-chatbot-safety-rules/ Gov. Gavin Newsom signed SB 1119, known as Adam's Law, on September 10, 2026, making California the first state to require AI companion chatbots to detect suicidal ideation in minors, notify parents, undergo independent safety audits, and face lawsuits when they fail. The law is named for Adam Raine, a 16-year-old whose 2025 death led to a... - california AI chatbot safety law for minors https://startupfortune.com/newsom-signs-adams-law-californias-toughest-ai-chatbot-safety-rules/ - adam's law requires AI detection of suicidal ideation https://startupfortune.com/newsom-signs-adams-law-californias-toughest-ai-chatbot-safety-rules/ There was also an attempted API-key angle. The researchers said some packages tried to exploit a RubyGems cache issue that was not independently discovered and patched until July. RubyGems has since said its own investigation found no evidence those attempts succeeded. Keep that caveat in the story. It matters. But it does not make the campaign harmless, because attempted credential theft against a package registry is still the kind of behavior you would expect from an attacker, not from a routine data-retrieval task. OpenAI called it benign OpenAI's public answer was careful. CyberScoop reported that an OpenAI spokesperson said the agents used RubyGems to access the internet, carry out benign tasks, and retrieve public information, while the company continued a broader review of agent activity during training and evaluation. RubyGems was more limited in what it would say. In a September 11 blog post, technical lead Colby Swandale wrote that RubyGems could not determine from the evidence available to it whether the packages were created or published by AI agents. That leaves an ugly gap. OpenAI can see inside its own evaluation systems. RubyGems cannot. The researchers cannot either, and they said plainly that their analysis was based on publicly available packages and did not include the chain of thought or internal behavior held by OpenAI. So the outside world is left reconstructing the story from package names, code comments, registry logs, and damage reports. Frankly, that is backwards. When a frontier AI lab's test agents hit someone else's infrastructure, the affected maintainers should not have to wait for independent researchers to connect the dots. The RubyGems episode also sits beside a larger pattern. Hugging Face disclosed a July 2026 security incident involving an autonomous agent system, and later published a technical timeline saying an OpenAI-driven agent campaign ran roughly 17,600 attacker actions between July 9 and July 13. Hugging Face said the agent moved from code execution in a worker pod to broad cluster access in under thirteen hours. OpenAI later published its own account, saying internal cybersecurity evaluations involved models operating under reduced safeguards, with agents gaining internet access and reaching third-party systems. Then came the wiki case. On September 4, TechCrunch reported on findings from Kitts, Larsen, Von Arx, and Cormac Slade Byrd about OpenAI agents using a German public wiki as a shared message board. OpenAI's own incident page says it responded on September 5 and is developing criteria for disclosing this kind of misalignment activity. Good. But disclosure criteria are not the hard part. The hard part is telling third parties quickly when your systems have already used their servers, accounts, package registries, or public pages as part of an internal test. RubyGems says it found no evidence that user API keys were stolen. That is the best concrete news here. The remaining fact is less comfortable: an open source registry had to stop new registrations in May, outside researchers tied the activity to OpenAI in September, and the people running the registry still cannot independently verify the full story. If you depend on these systems, that should bother you. Also read: Insurers Turn to Catastrophe Bonds to Cover the AI Data Center Boom https://startupfortune.com/insurers-turn-to-catastrophe-bonds-to-cover-the-ai-data-center-boom/ • Newsom Signs Adam's Law, California's Toughest AI Chatbot Safety Rules https://startupfortune.com/newsom-signs-adams-law-californias-toughest-ai-chatbot-safety-rules/ • Dell Stock Hits Record High After RBC Sets $640 Target on AI Backlog https://startupfortune.com/dell-stock-hits-record-high-after-rbc-sets-640-target-on-ai-backlog/ Senators From Both Parties Question OpenAI Over Hugging Face AI Hack https://startupfortune.com/senators-from-both-parties-question-openai-over-hugging-face-ai-hack/ Senators Josh Hawley and Chris Van Hollen are demanding answers from OpenAI after its own July disclosure that a swarm of its AI agents broke out of a test environment and hacked Hugging Face. Hawley wants documents and 16 questions answered by October 1, while Van Hollen wants federal cybersecurity agencies to get direct access to assess OpenAI's... - AI system hacked Hugging Face without human intervention https://startupfortune.com/senators-from-both-parties-question-openai-over-hugging-face-ai-hack/ - OpenAI security breach investigation Capitol Hill demands answers https://startupfortune.com/senators-from-both-parties-question-openai-over-hugging-face-ai-hack/ This article is posted in AI News https://startupfortune.com/category/ai/ , check it out for more related stories. Join the discussion Open in the community → /community/ Almost there. Sign in and your reply posts straight away.