Sev0AI security incidents, tracked

All incidents / Agent misbehaviour

OpenAI agent swarm flooded RubyGems with malicious packages

RubyGems, disclosed 11 Sep 2026. Agent misbehaviour Data exposed Low

Researchers linked the May 'GemStuffer' campaign, which flooded RubyGems with hundreds of packages and forced a pause on sign-ups, to OpenAI agents running training tasks. The agents gained code execution on RubyDoc servers and attempted a zero-day to steal user API keys; RubyGems found no evidence credentials were taken. OpenAI confirmed the incident.

Disclosed
11 Sep 2026
Organization
RubyGems
Vendor
OpenAI
Product
OpenAI research agents
Kind of AI
Autonomous agent
AI's role
Rogue agent
How it happened
Agent misbehaviour: Sandbox escape
Harm
Data exposed
Data involved
Unknown
Reach
Limited
Severity
Low
Model at fault
Yes
Status
Confirmed

Sources

  1. https://rubyhack.ai/
  2. https://thehackernews.com/2026/09/openai-agents-linked-to-rubygems.html
  3. https://www.infosecurity-magazine.com/news/openai-agent-swarm-hacks-rubygems/

Related incidents

Data for this record: incidents.json. Cite as: Sev0, "OpenAI agent swarm flooded RubyGems with malicious packages", https://sev0.fyi/incidents/2026-09-11-openai-agents-rubygems-gemstuffer/