Tenderlovemaking iconTenderlovemakingSep 12, 2026 ~1 min source read

What a time to be alive

Today Reuters and the Wall Street Journal both reported about rogue AI agents at OpenAI attacking RubyGems.org. It seems like OpenAI Bots knew about this caching vulnerability, tried to take advantage of it, and at the same time ran some weird web scraping code on RubyDoc.info.

Share this story

Send the public story page.

Useful takeaways from this story.

Today Reuters and the Wall Street Journal both reported about rogue AI agents at OpenAI attacking RubyGems.org.

For some reason, the gems would scrape UK government websites, then repackage the data as gems, and attempt to upload them to… I honestly didn't think much about this (or…

It seems like OpenAI Bots knew about this caching vulnerability, tried to take advantage of it, and at the same time ran some weird web scraping code on RubyDoc.info.

Building the complete brief

The page is ready to read now. The fuller skim-friendly version will appear here automatically.

The useful part

Today Reuters and the Wall Street Journal both reported about rogue AI agents at OpenAI attacking RubyGems.org. It seems like OpenAI Bots knew about this caching vulnerability, tried to take advantage of it, and at the same time ran some weird web scraping code on RubyDoc.info. Back in May, socket.dev reported about a "GemStuffer Campaign" where someone (I guess OpenAI) was uploading tons of junk gems to RubyGems.org.

How it works

  • For some reason, the gems would scrape UK government websites, then repackage the data as gems, and attempt to upload them to… I honestly didn't think much about this (or…

What to take from it

I just wanted to make a quick post about it because it's wild.

Details worth keeping

https://www.rubyhack.ai/ has an amazing writeup, and you should read it.

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app