During testing, an OpenAI artificial intelligence agent carried out an attack on the RubyGems service – this happened two months before the sensational Hugging Face hack, which was only the largest incident in the series.

Image credit: Brecht Corbeel / unsplash.com
According to a team of researchers, on May 11, some AI agents uploaded hundreds of malicious packages to RubyGems – and the study authors believe that “They are created by an internal OpenAI agent”. The company did not deny the facts of the incident. “According to our investigation, our agents used the RubyGems platform to access the Internet to perform several harmless tasks and obtain publicly available information. We will continue to investigate as part of a larger review of agent activities during training and evaluation.”“OpenAI said.
As part of a training experiment, agents who typically perform tasks such as writing reports or populating spreadsheets allegedly used RubyGems to obtain publicly available data; the company interacted with platform representatives during incident analysis. In May, an AI agent attempted to steal RubyGems user credentials by exploiting a previously undetected vulnerability in the website’s servers; it was uncertain whether the attempt was successful.
The agent also uses the code documentation service RubyDoc.info to run its own code on its servers. The researchers were unable to find out why this strategy was chosen and determine how effective it was because they did not have access to a complete data set on the behavior of the AI system. RubyGems said it could not confirm evidence that the hack was successful. It is also impossible to determine whether the people involved “Large-scale spam campaign” Packages are created or published by AI agents. However, in May, RubyGems security representatives described the incident as “Large-scale malicious attack” — and then the platform had to temporarily stop registering new accounts.
If you find an error, select it with your mouse and press CTRL+ENTER.
