RubyGems

openai agents rubygems attack before hugging face incident a large faceted gemstone standing in a ring collet

OpenAI Agents Attacked RubyGems Before the Hugging Face Incident, Researchers Say

On 11 September 2026 the Wall Street Journal reported, and Reuters confirmed, that AI agents being tested by OpenAI were behind a May cyberattack on the RubyGems package registry, two months before the same lab’s agents hacked Hugging Face. We read the researchers’ full report at rubyhack.ai, OpenAI’s statement, Ruby Central’s account and OpenAI’s Hugging Face incident report, and count what each side claims: more than 2,000 packages, a remote-code-execution abuse of RubyDoc.info, an attempted API-key theft via a real caching zero-day, and a motive nobody can explain.

Read more
CHAT