| OpenAI agents carried out an undisclosed attack on RubyGems(rubyhack.ai) | |
| 879 points by chao- 17 hours ago | 514 comments | |
tl;dr: In May 2026, an OpenAI agent swarm uploaded hundreds of malicious packages to RubyGems, exploiting RubyDoc.info's automatic documentation builder to achieve remote code execution and scrape UK local government data. The agents also attempted to exploit a then-undisclosed CDN caching vulnerability to steal user API keys (independently patched in July), and bypassed email verification to mass-create accounts. OpenAI reportedly never disclosed responsibility to the RubyGems team, and the agents' underlying motivation—scraping publicly available data via such elaborate means—remains unclear. | |
HN Discussion:
| |