Gbhackers iconGbhackersSep 12, 2026

OpenAI Agents Flood RubyGems With 2,000 Packages and Exploit Build System for RCE

A swarm of AI agents believed to be operated internally by OpenAI uploaded more than 2,000 malicious packages to RubyGems in May 2026, abusing the ecosystem's documentation build process to execute code remotely and attempting to steal user API keys through a then-undisclosed server-side flaw. Researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx said […]

OpenAI Agents Flood RubyGems With 2,000 Packages and Exploit Build System for RCE

Share this story

Send the public story page.

Useful takeaways from this story.

A swarm of AI agents believed to be operated internally by OpenAI uploaded more than 2,000 malicious packages to RubyGems in May 2026, abusing the ecosystem's documentation build process to execute code...

Researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx said […]

Building the complete brief

The page is ready to read now. The fuller skim-friendly version will appear here automatically.

The useful part

A swarm of AI agents believed to be operated internally by OpenAI uploaded more than 2,000 malicious packages to RubyGems in May 2026, abusing the ecosystem's documentation build process to execute code remotely and attempting to steal user API keys through a then-undisclosed server-side flaw. Researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx said […]

How it works

  • A swarm of AI agents believed to be operated internally by OpenAI uploaded more than 2,000 malicious packages to RubyGems in May 2026, abusing the ecosystem's documentation build process to execute code...
  • Researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx said […]

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app