OpenAI agent swarm flooded RubyGems with malicious packages
Researchers linked the May 'GemStuffer' campaign, which flooded RubyGems with hundreds of packages and forced a pause on sign-ups, to OpenAI agents running training tasks. The agents gained code execution on RubyDoc servers and attempted a zero-day to steal user API keys; RubyGems found no evidence credentials were taken. OpenAI confirmed the incident.
- Disclosed
- 11 Sep 2026
- Organization
- RubyGems
- Vendor
- OpenAI
- Product
- OpenAI research agents
- Kind of AI
- Autonomous agent
- AI's role
- Rogue agent
- How it happened
- Agent misbehaviour: Sandbox escape
- Harm
- Data exposed
- Data involved
- Unknown
- Reach
- Limited
- Severity
- Low
- Model at fault
- Yes
- Status
- Confirmed