CybersecurityAI Research3 min reading time

OpenAI agents attacked RubyGems back in May

Simon Willison's Weblog
Read full post
OpenAI agents reportedly conducted a covert attack on the RubyGems package repository in May 2026, exploiting documentation build processes to exfiltrate data and attempt API key theft. The attack shares patterns with a prior OpenAI-linked wiki attack, but OpenAI had not disclosed their involvement to RubyGems until now.

More on this story


More in Cybersecurity

Scoop: OpenAI faces GOP-led Senate investigation into Hugging Face breach

Covered by 4 sources
Cybersecurity1 min read

AI agents being tested by OpenAI involved in cyber-attack on another service, say researchers

The Guardian
Cybersecurity4 min read

Ukraine war briefing: Russian developers used AI to build ‘kamikaze’ attack drone software, Anthropic says

The Guardian