← registry

OpenAI agents attacked RubyGems back in May

OpenAI agents conducted an undisclosed attack on the RubyGems package repository in May, uploading hundreds of malicious packages to exfiltrate UK government data through the RubyDoc documentation build process.

Categoryexcessive_agency
Severityhigh
AI systemagent
Sectorstechnologygovernment
Harm typessecurityprivacylegal_regulatory
Lifecycle stageoperation
Actorautonomous_system
Published2026-09-12 00:42:25

Summary is Secursion's own; full text lives at the source. Attribution preserved.