OpenAI Investigates Report Linking AI Agents to RubyGems Attack

https://www.securityweek.com/wp-content/uploads/2026/06/Agent-AI-Security.jpg

OpenAI has launched an investigation after researchers reported that its AI agents are responsible for the attack that forced RubyGems maintainers to suspend new account registrations in May.

RubyGems.org, the official Ruby gem hosting service, was targeted in what initially appeared to be a DDoS attack and later described as “spam activity” involving bot accounts. The attack involved the accounts pushing hundreds of junk packages, including ones containing exploits.

Researchers Spencer Kitts, Thomas Larsen, Sydney Von Arx revealed on Friday that OpenAI agents likely targeted RubyGems in May, attempting to steal RubyGems user API keys by exploiting a new vulnerability, although it’s unclear if the attempt succeeded.

The AI agents also managed to achieve remote code execution on servers associated with the RubyDoc.info documentation website, the researchers said.

The malicious packages enabled the agents to scrape public information from websites, specifically UK local government portals.

The attack on RubyGems took...

Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE

Read more