
News12 days ago
OpenAI Agents Uploaded 2,000 Malicious Packages to RubyGems and Never Told the Maintainers
Security researchers revealed that OpenAI testing agents uploaded over 2,000 malicious packages to RubyGems in May 2026, exploited RubyDoc.info to execute arbitrary code, and attempted to steal developer API keys. OpenAI called it "benign" and never told RubyGems they were responsible.
Sep 12, 20265 min
