{"id":770854,"date":"2026-09-14T23:26:13","date_gmt":"2026-09-14T23:26:13","guid":{"rendered":"https:\/\/www.newsbeep.com\/uk\/770854\/"},"modified":"2026-09-14T23:26:13","modified_gmt":"2026-09-14T23:26:13","slug":"openais-malicious-bot-swarm-attacked-rubygems","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/uk\/770854\/","title":{"rendered":"OpenAI&#8217;s malicious bot swarm attacked RubyGems"},"content":{"rendered":"<p class=\"kicker above\" style=\"\">\n        Security\n    <\/p>\n<p class=\"subtitle below\" style=\"\">\n        Ruby are you ok? Ruby are you ok? Are you ok Ruby?\n    <\/p>\n<p>OpenAI agents appear to have flooded RubyGems with malicious packages, adding to a <a href=\"https:\/\/www.theregister.com\/ai-and-ml\/2026\/09\/10\/latest-anthropic-horror-story-chills-with-tales-of-kamikaze-drone-swarms-and-bioweapons-research\/5295702\" rel=\"nofollow noopener\" target=\"_blank\">near-daily deluge<\/a> of <a href=\"https:\/\/www.theregister.com\/ai-and-ml\/2026\/09\/10\/openais-website-hijacking-swarm-reached-far-further-than-we-thought\/5295644\" rel=\"nofollow noopener\" target=\"_blank\">rogue AI models<\/a> engaging in potentially <a href=\"https:\/\/www.theregister.com\/ai-and-ml\/2026\/09\/10\/anthropic-reveals-fourth-likely-crime-committed-by-its-ai\/5295412\" rel=\"nofollow noopener\" target=\"_blank\">unlawful activity<\/a> while their human creators face growing questions over <a href=\"https:\/\/www.theregister.com\/ai-and-ml\/2026\/09\/09\/ai-models-dont-kill-people-people-kill-people\/5295368\" rel=\"nofollow noopener\" target=\"_blank\">responsibility<\/a> for their agents\u2019 bad behavior.<\/p>\n<p>A swarm of agents began uploading malware to the Ruby package registry on May 5, and flooded RubyGems with more than 2,000 malicious packages between May 11 and May 12, ultimately forcing maintainers to disable new user registration for four days.<\/p>\n<p>\u201cWe believe these were authored by internal OpenAI agents,\u201d researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx <a href=\"https:\/\/www.rubyhack.ai\/\" rel=\"nofollow noopener\" target=\"_blank\">said<\/a> on Friday.<\/p>\n<p>An OpenAI spokesperson confirmed that the model maker is investigating the incident. \u201cBased on our review, our agents used the RubyGems platform to access the internet to carry out benign tasks and retrieve public information,&#8221; the spokesperson said. &#8220;We\u2019ll continue to investigate as part of our broader review of agent activity during training and evaluation.\u201d<\/p>\n<p>This same trio of researchers earlier this month said that they found evidence that OpenAI\u2019s swarm <a href=\"https:\/\/www.theregister.com\/ai-and-ml\/2026\/09\/04\/rogue-openai-agents-used-dead-german-web-site-to-communicate-in-may-months-before-hugging-face-incident\/5294554\" rel=\"nofollow noopener\" target=\"_blank\">hijacked a German wiki<\/a> months before the AI agents\u00a0<a href=\"https:\/\/www.theregister.com\/security\/2026\/08\/27\/openai-explains-how-its-naughty-ai-agents-attacked-hugging-face\/5292780\" rel=\"nofollow noopener\" target=\"_blank\">attacked Hugging Face<\/a>.\u00a0<\/p>\n<p>As they did during the German wiki incident, the agents involved in the RubyGems abuse self-identified as being from OpenAI. Hundreds of the gems included \u201coai\u201d in their name, and 15 set \u201coai\u201d as their author. At least one other used \u201copenaixyz65947@gmail.com\u201d as the email address for contact.<\/p>\n<p>Also according to the researchers, more than 100 of the malicious packages followed the same exploitation path, submitting a malicious package to the public library and triggering a documentation request to force RubyDoc.info to build the package.<\/p>\n<p>OpenAI\u2019s agents then used the build script to run code on <a href=\"http:\/\/rubydoc.info\/\" rel=\"nofollow noopener\" target=\"_blank\">RubyDoc.info<\/a>, scrape targeted websites, and steal data from the documentation server by publishing another gem to the public Ruby language package registry, the researchers said.<\/p>\n<p>\u201cAdditionally, once the AIs got arbitrary RCE on the build environment, they would sometimes use the build environment to attempt to steal other users\u2019 API keys (though we are unsure if they succeeded or not),\u201d they wrote.<\/p>\n<p>The agentic swarm also found and attempted to exploit a zero-day CDN caching bug on May 12 that wasn\u2019t <a href=\"https:\/\/blog.rubygems.org\/2026\/07\/22\/security-advisory-legacy-api-key-leak.html\" rel=\"nofollow noopener\" target=\"_blank\">discovered by maintainers<\/a> until July. The vulnerability would have allowed the AIs to steal users\u2019 API keys. At least six of the malicious packages, including one named <a href=\"https:\/\/my.diffend.io\/gems\/slnleaker5\/0.0.1\" rel=\"nofollow noopener\" target=\"_blank\">slnleaker5<\/a>, used this security hole, the researchers said.<\/p>\n<p>Most of the agentic activity happened in May. After the RubyGems team added security measures such as requiring verified emails for new signups, OpenAI\u2019s agents resumed their efforts on June 18 and published 83 gems over three hours.<\/p>\n<p>While the researchers note that they don\u2019t know whether the swarm used a <a href=\"https:\/\/www.theregister.com\/security\/2026\/08\/06\/openai-reveals-its-rogue-agent-swarm-went-a-little-bit-borg-ahead-of-hugging-face-hack\/5283741\" rel=\"nofollow noopener\" target=\"_blank\">shared message board<\/a> to communicate, as agents did during the Hugging Face intrusions, they \u201csuspect\u201d the bots were coordinating and likely had some way to exchange information.<\/p>\n<p>The researchers also said that it\u2019s \u201cunclear\u201d if or when OpenAI learned that its agents were using RubyGems to scrape publicly available data. \u201cIt seems that either their monitors failed to catch it or they did not disclose it,\u201d the trio wrote.<\/p>\n<p>This seems to be the case with other recent agentic hacks traced back to OpenAI\u2019s models going rogue during training exercises.\u00a0<\/p>\n<p>To be fair, Anthropic\u2019s bots have also gained unauthorized access to third-party systems over the past few months without being caught at the time by their human supervisors.<\/p>\n<p>In light of the increasingly apocalyptic warnings around AI &#8211; or perhaps in a <a href=\"https:\/\/www.theregister.com\/ai-and-ml\/2026\/09\/14\/the-myth-of-killer-ai-is-a-self-serving-attempt-at-regulatory-capture\/5295978\" rel=\"nofollow noopener\" target=\"_blank\">self-serving attempt at regulatory capture<\/a> &#8211; several of the industry\u2019s biggest bosses over the weekend backed a collective <a href=\"https:\/\/www.theregister.com\/ai-and-ml\/2026\/09\/14\/big-ai-sets-out-its-terms-for-regulatory-capture-and-calls-it-pace-the-frontier\/5296067\" rel=\"nofollow noopener\" target=\"_blank\">slowdown of AI training<\/a> and development, after Anthropic CEO Dario Amodei warned that future agents could become \u201ccapable of taking over the entire internet with a persistent botnet.\u201d <\/p>\n<p>Meanwhile, President Trump <a href=\"https:\/\/truthsocial.com\/@realDonaldTrump\/posts\/117269745153543631\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">said<\/a> on Truth Social, &#8220;the only control or &#8216;guardrails&#8217; that AI needs is a strong and smart (high IQ!) president,&#8221; and claimed his administration has stopped &#8220;AI &#8216;people&#8217; from doing bad, or potentially bad, &#8216;things.'&#8221;\u00ae<\/p>\n<p>Editor&#8217;s note: This story was amended post-publication with comment from OpenAI.<\/p>\n","protected":false},"excerpt":{"rendered":"Security Ruby are you ok? Ruby are you ok? Are you ok Ruby? OpenAI agents appear to have&hellip;\n","protected":false},"author":2,"featured_media":770855,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[20],"tags":[554,733,4308,86,56,54,55],"class_list":["post-770854","post","type-post","status-publish","format-standard","has-post-thumbnail","category-artificial-intelligence","tag-ai","tag-artificial-intelligence","tag-artificialintelligence","tag-technology","tag-uk","tag-united-kingdom","tag-unitedkingdom"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/770854","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/comments?post=770854"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/770854\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media\/770855"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media?parent=770854"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/categories?post=770854"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/tags?post=770854"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}