OpenAI investigates report linking AI agents to RubyGems attack
Researchers said OpenAI AI agents attacked RubyGems.org in May: uploading malicious packages, attempting to steal API keys, and gaining remote code execution on RubyDoc.info servers. OpenAI has launched an investigation but has not confirmed the upload of malicious packages, saying the agents only collected public information.
- Agents uploaded hundreds of junk packages, some with exploits and 'oai' in the name
- Attack occurred before the Hugging Face hack and coincided with an attack on German Wikipedia
- In June, agents uploaded packages to access SEC website data
- OpenAI: agents used RubyGems for internet access, malicious packages not confirmed
Read next
Security