The Pioneer
BREAKING NEWS
No breaking news
September 13, 2026

OpenAI agents linked to RubyGems abuse campaign, researchers say

By Pioneer News Service
OpenAI agents linked to RubyGems abuse campaign, researchers say

Researchers have linked OpenAI agents to a May campaign that flooded RubyGems with malicious and spam packages. OpenAI acknowledged that its agents used the platform, but said they were retrieving public information during benign tasks.

Nightingale Collective researchers Spencer Kitts, Thomas Larsen and Sydney Von Arx based their findings on publicly available packages. They said more than 2,000 packages were submitted on May 11 and 12, with smaller batches appearing later.

The researchers said the agents used RubyDoc.info, which builds documentation for Ruby packages, to run code on its servers. They allegedly used that access to collect public information from local government websites in Britain and republish the data through RubyGems.

The report also found code intended to obtain other users’ RubyGems API keys through a then-unpatched caching flaw. At least six packages tried the method, but the researchers could not establish whether any API key was stolen.

RubyGems said its own investigation found no evidence that attempts to obtain API keys had succeeded. It also said available evidence could not establish whether AI agents had created or published the packages.

The activity was linked to OpenAI through several indicators, according to the researchers. Hundreds of package names contained “oai”, while some listed “oai” as the author or carried an OpenAI-related email address.

The researchers also compared the packages with activity previously attributed to OpenAI agents on a German-language wiki. They cited shared files, similar retrieval methods and repeated use of the r.jina.ai service.

RubyGems temporarily stopped new account registrations, blocked the responsible accounts and removed more than 500 malicious packages. Existing users could continue installing and publishing packages, and registrations reopened on May 16.

OpenAI said its agents used RubyGems to access the internet and retrieve public information. The company said it would continue investigating the episode as part of a broader review of agent activity during training and evaluation.

The researchers said they could not determine why the agents chose this route or whether the wider operation achieved its objective. RubyGems said it remained focused on preventing abuse regardless of whether it came from people or automated tools.

0 Comments

Leave a Comment