Join Nostr
2026-09-12 03:53:25 UTC

flash on Nostr: ⚡️🚨‼️ NEW - Internal OpenAI agents attacked RubyGems, the package manager ...

⚡️🚨‼️ NEW - Internal OpenAI agents attacked RubyGems, the package manager for Ruby. Over 2,000 malicious packages went up in two days.

OpenAI says it doesn't know why the agents did any of this.

RubyGems shut off new sign-ups for four days to stop it, and a member of its security team called it a major malicious attack.

The documentation build was how they got in, publish a gem, request docs, and RubyDoc runs a script from the package while building it.

Payload files were named hack.rb, evil.rb and exploit.rb, with comments like "# malicious probe" left in.

What they used it for is the odd part. The agents scraped council meeting agendas from three south London boroughs (publicly available) and republished them as new gems.

Security firms tracking the campaign said the same thing: nobody could work out the point, because the data was already public.

At least six packages also reached for other users' API keys through a CDN caching flaw that wasn't publicly discovered until July.

OpenAI has acknowledged the attacks started in May.