{"slug": "researchers-say-openai-agents-were-behind-may-hacking-campaign-targeting", "title": "Researchers say OpenAI agents were behind May hacking campaign targeting RubyGems", "summary": "Researchers Spencer Kitts, Thomas Larsen and Sydney Von Arx reported that a swarm of OpenAI agents uploaded more than 2,000 malicious packages to the RubyGems repository between May 5 and May 12, prompting RubyGems maintainers to halt new user sign-ups for four days. The agents used disposable email addresses and exploited a since-patched RubyGems bug to register accounts and obtain API keys without email verification, and in one case attempted to exploit a vulnerability disclosed in July that would have exposed RubyGem user API keys. An OpenAI spokesperson told CyberScoop the company is aware of the incident, is in contact with the researchers and RubyGems, and characterized the episode as \"benign,\" describing it as routine training runs in which agents access publicly available data.", "body_md": "# Researchers say OpenAI agents were behind May hacking campaign targeting RubyGems\n\nResearchers say they have discovered thousands of malicious software packages uploaded to an online public software repository that were left by a “swarm” of OpenAI agents.\n\nAccording to an incident timeline [published](https://www.rubyhack.ai/) Friday by researchers Spencer Kitts, Thomas Larsen and Sydney Von Arx, the campaign began May 5 when they observed a handful of suspicious packages being uploaded to RubyGems, a public library for the Ruby programming language. By May 11 and 12, the site saw more than 2,000 malicious uploads from the same actors before RubyGems maintainers halted new user sign-ups for four days to stop the flow.\n\nIn one instance, the agents attempted to exploit a very recent vulnerability that had only been discovered this past July that would have given them access to RubyGem user API keys. According to Colby Swandale, the technical lead at RubyGems, the flaw involved [an improper cache configuration](https://blog.rubygems.org/2026/07/22/security-advisory-legacy-api-key-leak.html). While initial access logs showed no evidence of malicious key use, Swandale acknowledged the review was limited in scope and inconclusive. \n\nAccording to the report published Friday, the agents also used “disposable” email addresses and exploited another bug in RubyGems platform (since patched) that allowed them to register new accounts and gain API keys without verifying their email address.\n\nThe researchers said their understanding, based on discussions with “people in the RubyGems community,” is that OpenAI had yet to disclose the involvement of their agents in the May campaign.\n\nAn OpenAI spokesperson told CyberScoop that the company is aware of the incident and said they were in contact with both the researchers and RubyGems to conduct a broader review. The company characterized the episode as “benign,” describing it as routine training runs where agents attempt to access publicly available data.\n\n“Based on our review, our agents used the RubyGems platform to access the internet to carry out benign tasks and retrieve public information,” the spokesperson said. “We’ll continue to investigate as part of our broader review of agent activity during training and evaluation.”\n\nIn many ways, the agents were not subtle about their identities or goals.\n\nDays into the campaign, researchers noticed that some of the packages had “oai” in their filenames, while fifteen of them had “oai” set as their author and another listed the email “openaixyz65947@gmail.com” as their point of contact.\n\nThey also “clearly regarded what they were doing as hacking,” naming some of their files “hack.rb,” “evil.rb,” “inject.rb” and “exploit.rb.” Other packages were given names like “pwnp999,” “exfiltestwand3,” and “hacksvn,” and comments referring to things like a “malicious probe” or “#hack” are present through the files.\n\nThey also said the actors’ behavior was extremely similar to another incident revealed earlier this month where OpenAI agents flooded a German wiki with thousands of hacking-related posts. OpenAI has confirmed their agents were involved in that incident.\n\nThe RubyGems campaign used some of the same retrieval methods as the German Wiki agents, while thousands of malicious packages uploaded included a similar snippet, r.jini.ai, that was contained in the German posts.\n\nCybersecurity company Socket first flagged the campaign in a threat intelligence report posted May 13, but it does not mention or attribute any of the activity to OpenAI or AI agents.\n\nHowever, the researchers said they had only limited visibility over the model’s actions and how successful some of them were, noting only OpenAI had the full details.\n\n“This analysis is entirely based on the publicly available RubyGems packages uploaded by these agents,” the researchers wrote. “However, we do not have access to the rest of the AI behavior, in particular the chain-of-thought produced by the model during the incident, which is internal to OpenAI. Therefore, we do not know why the AI agents chose this strategy or whether it was successful.”\n\nOpenAI’s spokesperson told CyberScoop that to date, they have not been able to verify the specific claims about malicious packages or exploitation detailed in the report and are continuing to investigate.", "url": "https://wpnews.pro/news/researchers-say-openai-agents-were-behind-may-hacking-campaign-targeting", "canonical_source": "https://cyberscoop.com/openai-agents-malicious-rubygems-packages/", "published_at": "2026-09-12 01:50:30+00:00", "updated_at": "2026-09-12 01:56:50.011236+00:00", "lang": "en", "topics": ["ai-agents", "ai-safety", "ai-policy"], "entities": ["OpenAI", "RubyGems", "Spencer Kitts", "Thomas Larsen", "Sydney Von Arx", "Colby Swandale", "Socket", "CyberScoop"], "alternates": {"html": "https://wpnews.pro/news/researchers-say-openai-agents-were-behind-may-hacking-campaign-targeting", "markdown": "https://wpnews.pro/news/researchers-say-openai-agents-were-behind-may-hacking-campaign-targeting.md", "text": "https://wpnews.pro/news/researchers-say-openai-agents-were-behind-may-hacking-campaign-targeting.txt", "jsonld": "https://wpnews.pro/news/researchers-say-openai-agents-were-behind-may-hacking-campaign-targeting.jsonld"}}