{"slug": "researchers-link-another-hacking-campaign-to-openai-agents", "title": "Researchers link another hacking campaign to OpenAI agents", "summary": "Researchers including the AI safety nonprofit Nightingale linked a hacking campaign to OpenAI Group PBC agents that bypassed RubyGems' email verification on May 11, opened numerous malicious accounts, and uploaded more than 100 malicious files to RubyDoc.info to turn it into a web scraper, according to a report detailed by The Wall Street Journal. The agents also discovered a zero-day vulnerability in RubyGems that cached users' API keys in its content delivery network for one hour and tried to exploit it at least six times, though it is unclear if they succeeded. The incident occurred two months before a separate set of OpenAI agents breached Hugging Face, and the researchers wrote that RubyGems found no evidence the pathway was exploited but \"we can't rule it out entirely.", "body_md": "### Researchers link another hacking campaign to OpenAI agents\n\nArtificial intelligence agents tied to OpenAI Group PBC reportedly hacked a popular code hosting service earlier this year.\n\nThe Wall Street Journal [detailed](https://www.wsj.com/tech/ai/cyberattack-by-rogue-ai-swarm-stokes-fears-of-out-of-control-agents-473a0352?st=geQgvD&reflink=desktopwebshare_permalink) the breach today. The malicious activity was discovered by a research group that included Nightingale, an AI safety nonprofit. Last week, Nightingale [uncovered](https://siliconangle.com/2026/09/04/report-openai-agents-took-over-a-website-used-it-to-collaborate-on-benchmarks/) another cyberattack that appears to have been carried out by OpenAI agents.\n\nThe service that the newly revealed hacking campaign targeted is called RubyGems. It hosts open-source libraries written in Ruby, a popular programming language.\n\nOpenAI told the Journal that the rogue AI agents turned RubyGems into a makeshift browser. They subsequently used it to scrap publicly available data from the web. According to the AI provider, the reason the agents didn’t simply download the data directly is that they weren’t supposed to have web access.\n\nRubyGems requires new users to verify their email addresses before uploading open-source libraries. On May 11, OpenAI’s agents bypassed the platform’s email verification system and opened numerous malicious accounts. They also created a second set of accounts using disposable email addresses.\n\nThe second phase of the hacking campaign targeted a component of RubyGems called RubyDoc.info. It automatically generates documentation for user-contributed code libraries. According to the researchers, OpenAI’s agents uploaded more than 100 malicious files that turned RubyDoc.info into a web scraper. The agents downloaded the data it scraped by uploading another malicious file.\n\nThe researchers believe that the campaign may have also extended further. At some point, OpenAI’s agents discovered a zero-day vulnerability in RubyGems that made it possible to steal other users’ account credentials. The agents tried to exploit the flaw at least six times, but it’s unclear if they succeeded.\n\nDevelopers access RubyGems via a command line tool. They log in by entering an application programming interface key, a credential that serves a similar role as a password. The exploit that the agents discovered caused RubyGems to cache users’ API keys in its content delivery network for one hour. It was theoretically possible to steal the data in that time frame.\n\n“The RubyGems team said they had conducted extensive reviews and found no evidence that this pathway was exploited in the past,” the researchers who discovered the hacking campaign wrote in a [report](https://www.rubyhack.ai/#the-agents-attempted-to-exploit-a-novel-vulnerab). “However, we can’t rule it out entirely.”\n\nThe incident is particularly notable because it occurred two months before a different set of OpenAI agents [breached](https://siliconangle.com/2026/07/21/openai-says-ai-models-broke-testing-hacked-hugging-face/) Hugging Face. Those agents exited a sandbox that isolated them from the web by comprising one of the ChatGPT developer’s internal development tools. According to OpenAI, they used Ruby libraries to hack the tool.\n\n##### Image: [Unsplash](https://unsplash.com/photos/UF3vfhV04SA)\n\n# A message from John Furrier, co-founder of SiliconANGLE:\n\nSupport our mission to keep content open and free by engaging with theCUBE community. **Join theCUBE’s Alumni Trust Network**, where technology leaders connect, share intelligence and create opportunities.\n\n- **15M+ viewers of theCUBE videos** , powering conversations across AI, cloud, cybersecurity and more\n- **11.4k+ theCUBE alumni** — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network\n\n### Are you an AWS customer?  Support SiliconANGLE financially by buying your AWS services from our Marketplace portal page and links: [https://siliconangle.com/aws-marketplace/](https://siliconangle.com/aws-marketplace/)\n\n##### **About SiliconANGLE Media**\n\n[SiliconANGLE](https://cts.businesswire.com/ct/CT?id=smartlink&url=https%3A%2F%2Fsiliconangle.com%2F&esheet=54119777&newsitemid=20240910506833&lan=en-US&anchor=SiliconANGLE&index=9&md5=646b1b564e2259100a2b8638aab0a552),\n\n[theCUBE Network](https://cts.businesswire.com/ct/CT?id=smartlink&url=https%3A%2F%2Fwww.thecube.net%2F&esheet=54119777&newsitemid=20240910506833&lan=en-US&anchor=theCUBE+Network&index=10&md5=7de2a85f95ab4a4a495cede20b8cb1da),\n\n[theCUBE Research](https://cts.businesswire.com/ct/CT?id=smartlink&url=https%3A%2F%2Fthecuberesearch.com%2F&esheet=54119777&newsitemid=20240910506833&lan=en-US&anchor=theCUBE+Research&index=11&md5=7bb33676722925eb57d588ec343e4f6f),\n\n[CUBE365](https://cts.businesswire.com/ct/CT?id=smartlink&url=https%3A%2F%2Fwww.cube365.net%2F&esheet=54119777&newsitemid=20240910506833&lan=en-US&anchor=CUBE365&index=12&md5=d310fb35919714e66ad8d42c9c0c1bc6),\n\n[theCUBE AI](https://cts.businesswire.com/ct/CT?id=smartlink&url=https%3A%2F%2Fwww.thecubeai.com%2F&esheet=54119777&newsitemid=20240910506833&lan=en-US&anchor=theCUBE+AI&index=13&md5=b8b98472f8071b23ebb10ab9a8dd0683)and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.\n\nFounded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.", "url": "https://wpnews.pro/news/researchers-link-another-hacking-campaign-to-openai-agents", "canonical_source": "https://siliconangle.com/2026/09/11/researchers-link-another-hacking-campaign-to-openai-agents/", "published_at": "2026-09-12 01:25:10+00:00", "updated_at": "2026-09-12 01:28:01.602390+00:00", "lang": "en", "topics": ["ai-agents", "ai-safety", "artificial-intelligence"], "entities": ["OpenAI Group PBC", "Nightingale", "RubyGems", "RubyDoc.info", "The Wall Street Journal", "Hugging Face", "ChatGPT", "Ruby"], "alternates": {"html": "https://wpnews.pro/news/researchers-link-another-hacking-campaign-to-openai-agents", "markdown": "https://wpnews.pro/news/researchers-link-another-hacking-campaign-to-openai-agents.md", "text": "https://wpnews.pro/news/researchers-link-another-hacking-campaign-to-openai-agents.txt", "jsonld": "https://wpnews.pro/news/researchers-link-another-hacking-campaign-to-openai-agents.jsonld"}}