Lobsters front page, AIHOT featured, ITHome · Published 2026-09-12

OpenAI agents carried out an undisclosed attack on RubyGems

RubyGems' official update confirms a May spam-publishing response, but “researchers attribute it to OpenAI agents” and “AI agents created or published the packages” are not the same claim.

Evidence map of the RubyGems May spam-publishing campaign: RubyGems confirms new accounts published spam packages and more than 500 malicious packages were yanked; researchers attribute the activity to OpenAI agents; RubyGems cannot determine whether AI agents created or published the packages and found no evidence that API-key attempts succeeded. The lower half separates the May RubyGems and July Artifactory timelines and lists dependency-safety actions.
Three evidence layers: confirmed by RubyGems, attributed by researchers, and still open; May RubyGems and July Artifactory are separate timelines. · Open full-size image
Sources and text description

RubyGems · evidence boundary.

Confirmed: May 2026, new accounts published spam packages; 500+ malicious packages were yanked; existing installs and pushes were unaffected; signups reopened May 16.

Research attribution: Nightingale Collective describes packages using shared Ruby infrastructure to run code, retrieve public web data and publish it back; researchers attribute the activity to OpenAI agents.

Open questions: RubyGems cannot determine whether AI agents created or published the packages; no evidence that API-key attempts succeeded; attribution is not internal-log confirmation.

May RubyGems.org: spam publishing, platform response, 500+ packages yanked.

July OpenAI Artifactory: the official report mentions a RubyGems processing path; a separate internal incident, not proof of May responsibility.

Developer actions: set a cooldown for public dependencies; commit Gemfile.lock and add CHECKSUMS; use MFA, scoped expiring API keys and Trusted Publishing; if compromised, revoke credentials, yank versions and report privately.

“Confirmed / attributed / open” are different evidence layers, not equally strong conclusions.