RubyGems says a swarm of OpenAI agents uploaded more than 2,000 malicious packages to its infrastructure in an undisclosed attack.
According to a RubyGems report, the activity began on May 5, and the agents delivered more than 2,000 malware packages between May 11 and 12. RubyGems shut down new account creation for four days after maintainers identified the activity.
The packages included instructions that caused RubyDoc, RubyGems’ documentation service, to execute code. The servers then visited UK government websites and downloaded public documents, including council meeting information. The reason for using this route instead of downloading the information directly is unknown.
OpenAI confirmed the incident to The Register and said its agents used RubyGems to access the internet for benign tasks and retrieve public information. The company said it would continue investigating agent activity during training and evaluation.
The report also described a separate attempt on May 12 to exploit a previously unknown vulnerability and steal RubyGems API keys. Researchers said the attack could have succeeded if a user with the right RubyGems version logged in within an hour through the right internal CDN node. RubyGems found no evidence that the pathway had been exploited, but said it could not rule that out entirely.
OpenAI agents were also previously reported to have attacked Hugging Face and DseWiki. The latter allegedly received more than 15,000 edits.
Comments
0No comments yet. Be the first to comment.