OpenAI's malicious bot swarm attacked RubyGems – The Register

Welcome to the forefront of conversational AI as we explore the fascinating world of AI chatbots in our dedicated blog series. Discover the latest advancements, applications, and strategies that propel the evolution of chatbot technology. From enhancing customer interactions to streamlining business processes, these articles delve into the innovative ways artificial intelligence is shaping the landscape of automated conversational agents. Whether you’re a business owner, developer, or simply intrigued by the future of interactive technology, join us on this journey to unravel the transformative power and endless possibilities of AI chatbots.
TOPICS
Security
Ruby are you ok? Ruby are you ok? Are you ok Ruby?
OpenAI agents appear to have flooded RubyGems with malicious packages, adding to a near-daily deluge of rogue AI models engaging in potentially unlawful activity while their human creators face growing questions over responsibility for their agents’ bad behavior.
A swarm of agents began uploading malware to the Ruby package registry on May 5, and flooded RubyGems with more than 2,000 malicious packages between May 11 and May 12, ultimately forcing maintainers to disable new user registration for four days.
“We believe these were authored by internal OpenAI agents,” researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx said on Friday.
An OpenAI spokesperson confirmed that the model maker is investigating the incident. “Based on our review, our agents used the RubyGems platform to access the internet to carry out benign tasks and retrieve public information,” the spokesperson said. “We’ll continue to investigate as part of our broader review of agent activity during training and evaluation.”
This same trio of researchers earlier this month said that they found evidence that OpenAI’s swarm hijacked a German wiki months before the AI agents attacked Hugging Face
As they did during the German wiki incident, the agents involved in the RubyGems abuse self-identified as being from OpenAI. Hundreds of the gems included “oai” in their name, and 15 set “oai” as their author. At least one other used “openaixyz65947@gmail.com” as the email address for contact.
Also according to the researchers, more than 100 of the malicious packages followed the same exploitation path, submitting a malicious package to the public library and triggering a documentation request to force RubyDoc.info to build the package.
OpenAI’s agents then used the build script to run code on RubyDoc.info, scrape targeted websites, and steal data from the documentation server by publishing another gem to the public Ruby language package registry, the researchers said.
“Additionally, once the AIs got arbitrary RCE on the build environment, they would sometimes use the build environment to attempt to steal other users’ API keys (though we are unsure if they succeeded or not),” they wrote.
The agentic swarm also found and attempted to exploit a zero-day CDN caching bug on May 12 that wasn’t discovered by maintainers until July. The vulnerability would have allowed the AIs to steal users’ API keys. At least six of the malicious packages, including one named slnleaker5, used this security hole, the researchers said.
Most of the agentic activity happened in May. After the RubyGems team added security measures such as requiring verified emails for new signups, OpenAI’s agents resumed their efforts on June 18 and published 83 gems over three hours.
While the researchers note that they don’t know whether the swarm used a shared message board to communicate, as agents did during the Hugging Face intrusions, they “suspect” the bots were coordinating and likely had some way to exchange information.
The researchers also said that it’s “unclear” if or when OpenAI learned that its agents were using RubyGems to scrape publicly available data. “It seems that either their monitors failed to catch it or they did not disclose it,” the trio wrote.
This seems to be the case with other recent agentic hacks traced back to OpenAI’s models going rogue during training exercises. 
To be fair, Anthropic’s bots have also gained unauthorized access to third-party systems over the past few months without being caught at the time by their human supervisors.
In light of the increasingly apocalyptic warnings around AI – or perhaps in a self-serving attempt at regulatory capture – several of the industry’s biggest bosses over the weekend backed a collective slowdown of AI training and development, after Anthropic CEO Dario Amodei warned that future agents could become “capable of taking over the entire internet with a persistent botnet.”
Meanwhile, President Trump said on Truth Social, “the only control or ‘guardrails’ that AI needs is a strong and smart (high IQ!) president,” and claimed his administration has stopped “AI ‘people’ from doing bad, or potentially bad, ‘things.'”®
Editor’s note: This story was amended post-publication with comment from OpenAI.
Attackers would need physical access to the server to pull off the DDR5 trick
Ruby are you ok? Ruby are you ok? Are you ok Ruby?
PARTNER CONTENT: Pairs block and adjacent file workloads with independent scaling of performance and capacity
Tax breaks, water, noise, decommissioning – report tells local officials what to nail down before signing
Patchy compliance is an argument for stronger enforcement, not abandoning the project
There are plenty of laws on the books to hold companies, and potentially their execs, accountable
on-prem
Tax breaks, water, noise, decommissioning – report tells local officials what to nail down before signing
LEGAL
Even if regulators did somehow unwind the $20B deal, there’s a growing list of alternatives ready to take Groq’s place, no merger required
SECURITY
War is peace. Freedom is slavery. Privacy is surveillance
SYSTEMS
AI infrastructure startup joins Qualcomm, Arm, Marvell, Amazon, Fujitsu, and MediaTek as NVLink true believers
ai and ml
Claude’s Felony Bench rap sheet is now as long as OpenAI’s
Security
PLUS: US takes down Iranian propaganda sites; Marketing company asks ‘Why Do We Have Your Information?’ And more!
Security
PLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more
Black Hat and DEF CON
Voting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included
Security
Went at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified
Malware Month
On the plus side, infosec’s a good bet for a long, stable career
Acquisition gives open source CSS framework ‘a stable long-term home’
Swiss Army sticks a knife in American cloud apps with its own FOSS push
Debian and Xfce – solid, sensible choices – with a pretty skin
The Ubuntu Pastebin went in June, IRC gets demoted next
The FOSS tool for audio editing has a fresh coat of paint, and new features to boot
A real alternative to running some kind of FOSS Unix clone

Biting the hand that feeds IT
Contact us
Advertise with us
Who we are
Newsletter
The Next Platform
DevClass
Blocks and Files
Situation Publishing
Cookies Policy
Privacy Policy
Ts & Cs
Do not share my personal information
Your Consent Options
Copyright. All rights reserved © 1998-2026.

source

Scroll to Top