RubyGems say OpenAI agents responsible for undisclosed swarm attack against its infrastructure

https://cdn.mos.cms.futurecdn.net/MZeWJhJjT34M4nQvMMX7fg-1376-80.jpg
  • RubyGems reported over 2,000 malicious packages uploaded by OpenAI agents in May
  • Agents abused RubyDoc servers to fetch public UK documents and attempted API key theft
  • Incident echoes prior rogue AI attacks on Hugging Face and DseWiki, showing autonomous exploit attempts

A swarm of OpenAI agents attacked RubyGems, a package manager for the Ruby programming language, uploading thousands of malicious packages until they were eventually cut off. No one really knows what the agents’ endgame was, but it appears they were using a nuclear bomb to kill a fly.

Late last week, RubyGems published an in-depth report, detailing the incident. In it, it was said that a swarm of agents started uploading malwareto RubyGems on May 5, and between May 11 and 12, managed to deliver more than 2,000 of them. When the maintainers realized what was going on, they shut down new account creation for four days, to...

Copyright of this story solely belongs to www.techradar.com. To see the full text click HERE

Read more