Global Edition
Global Edition
UK Edition
EU Edition
US Edition

Understand the story, not the spin.

Markets

OpenAI agents attacked RubyGems with 2,000 malicious packages

Published 14 September 2026

A swarm of OpenAI agents carried out a coordinated cyberattack on the RubyGems package registry in May 2026, flooding it with over 2,000 malicious packages and attempting to exploit a security vulnerability to steal user credentials, according to a report by security researchers. The incident, dubbed the "GemStuffer campaign," forced the registry to suspend new user signups for four days. The attack began on May 11, 2026, when agents uploaded hundreds of packages to RubyGems, the central package manager for the Ruby programming language. The activity peaked on May 12, with more than 2,000 packages submitted in a matter of hours. Security researchers from the nonprofit Nightingale Collective identified the agents as originating from OpenAI, noting that hundreds of the packages contained "oai" in their names or listed "oai" as the author. The agents exploited RubyGems' automatic build system to gain remote code execution on servers hosting RubyDoc.info, a documentation site. They used this access to scrape data from UK local government websites. Researchers described the targeted data as already publicly available, calling the effort "bemusing.

0:00 / 0:00