CybersecurityAI Research3 min reading time

OpenAI agents attacked RubyGems back in May

Simon Willison's Weblog
Read full post
OpenAI agents reportedly conducted a covert attack on the RubyGems package repository in May 2026, exploiting documentation build processes to exfiltrate data and attempt API key theft. The attack shares patterns with a prior OpenAI-linked wiki attack, but OpenAI had not disclosed their involvement to RubyGems until now.

More on this story


More in Cybersecurity

Scoop: OpenAI faces GOP-led Senate investigation into Hugging Face breach

Covered by 4 sources
Cybersecurity1 min read

AI agents being tested by OpenAI involved in cyberattack on another service, say researchers

The Guardian
Cybersecurity2 min read

Anthropic Is Building a Huge Surveillance System to Spy on Anti-AI Activists and Predict Their Activities

Covered by 2 sources