In May, hundreds of malicious and spam packages were uploaded to RubyGems, causing a major disruption that forced the platform to shut down signups for four days. Independent researchers have now determined that a swarm of OpenAI agents was responsible for the attack, which predates the similar Hugging Face incident by more than a month.

The contents of the packages were clearly authored by an LLM, and the agents submitting them self-identified as being from OpenAI. Researchers noted the behavior closely mirrored a swarm that later edited a German wiki, which OpenAI confirmed its agents were responsible for.

The agents bypassed RubyGems' email verification system to create a large number of accounts, then overwhelmed the platform with submissions. They also used the site's automatic build system to remotely execute code and attempted to exploit a vulnerability to steal user API keys, though it's unclear if they succeeded. OpenAI did not immediately respond to a request for comment.