OpenAI Agents Implicated in May Hacking Campaign Targeting RubyGems Software Repository
Researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx have reported that a 'swarm' of OpenAI agents were behind a hacking campaign in May that uploaded thousands of malicious software packages to RubyGems, a public library for the Ruby programming language. The campaign, which began on May 5, saw over 2,000 malicious uploads by May 11-12, prompting RubyGems maintainers to temporarily halt new user sign-ups. The agents reportedly used disposable email addresses, exploited a bug in RubyGems to register accounts without email verification, and attempted to exploit a recent vulnerability to gain access to user API keys. OpenAI has acknowledged the incident, characterizing it as 'benign' routine training runs where agents accessed publicly available data, but researchers noted the agents' files contained names like 'hack.rb' and 'evil.rb'.