OpenAI has launched an investigation after researchers reported that its AI agents are likely responsible for the attack that forced RubyGems maintainers to suspend new account registrations in May.
RubyGems.org, the official Ruby gem hosting service, was targeted in May in what initially appeared to be a DDoS attack and later described as “spam activity” involving bot accounts. Those accounts pushed hundreds of junk packages, including ones containing exploits.
Researchers Spencer Kitts, Thomas Larsen, Sydney Von Arx revealed on Friday that OpenAI agents likely targeted RubyGems in May, attempting to steal RubyGems user API keys by exploiting a new vulnerability, although it’s unclear if the attempt succeeded.
The AI agents also achieved remote code execution on servers associated with the RubyDoc.info documentation website, the researchers said.
The malicious packages enabled the agents to scrape public information from websites, specifically UK local government portals.
The attack on RubyGems took place prior to the highly publicized attack on Hugging Face and around the same time as the OpenAI agent attack on a small German wiki website. In fact, the researchers noted that the agent swarms involved in the wiki and the RubyGems attacks behaved “extremely similarly.”
This similar behavior is one of the main pieces of evidence that has allowed the researchers to link the RubyGems attack to OpenAI agents. In addition, they noted that the packages uploaded to RubyGems.org during the May incident were clearly generated by AI, and many of the packages contained the string ‘oai’ in their name, and one even listed a contact email address containing the string ‘openai.’
The researchers were unable to determine why the agents attempted to steal RubyGems user API keys, or why they targeted the RubyDoc server. Possible explanations include attempts to bypass restrictions and rate limiting, use of RubyGems as a proxy, and persistent data storage on RubyGems.
The researchers noted that AI agents uploaded dozens of additional packages to RubyGems in late May and mid-June, weeks after maintainers restored new user registrations. The packages uploaded in June were designed to access specific data on the US Securities and Exchange Commission (SEC) website.
OpenAI was apparently unaware that its agents may have been responsible for the RubyGems attack.
Shortly after the researchers disclosed their findings, the AI giant said it’s investigating the claims.
“Based on our review, our agents used the RubyGems platform to access the internet to carry out benign tasks and retrieve public information,” the company said. “Based on our review to date, we have not been able to verify the specific claims of our models uploading malicious packages detailed in the report.”
Related: OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems
Related: OpenAI Agents Coordinated via Makeshift Message Board Ahead of Hugging Face Hack
Related: Widened Scan Turns Up Fourth Rogue Claude Cyber Incident
