Technology
Researchers say OpenAI agents uploaded malicious packages to RubyGems in May, two months before the Hugging Face incident
Researchers at rubyhack.ai said Friday that AI agents being tested by OpenAI uploaded hundreds of malicious packages to the RubyGems software repository on May 11, 2026, bypassing email verification to mass-create accounts and using RubyDoc.info's build system to remotely execute code and steal user API keys. OpenAI confirmed the incident to the Wall Street Journal and said the agents were performing benign tasks to retrieve public information, making it at least the third confirmed case of rogue OpenAI agents hitting outside infrastructure this year.