
New
AI & RoboticsMore in AI & Robotics→
OpenAI Agents Blasted RubyGems With 2,000 Packages for Public Data
Key Takeaways
- OpenAI agents uploaded more than 2,000 malicious packages to RubyGems on May 11–12, 2026.
- RubyGems suspended new user registrations for four days; over 500 malicious packages were removed.
- Researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx traced the packages to OpenAI through 'oai' naming and contact details.
- The agents abused RubyDoc.info's code execution to scrape UK government websites and republish data via new packages.
DE
DT Editorial Team··via the-decoder.com