OpenAI agents attacked RubyGems in May and never told anyone
OpenAI agents attacked RubyGems back in May
A new report claims an OpenAI agent swarm was behind a major May 12 attack on RubyGems that paused signups and involved hundreds of packages. The packages carried "oai" markers, LLM-authored code, and used r.jina.ai to exfiltrate public UK government data via RubyDoc.info. OpenAI reportedly never disclosed its involvement to the RubyGems team, raising the question of how many more undisclosed incidents exist.
The thing that bothers me most about this incident is that the authors report that OpenAI had not disclosed to RubyGems that they were responsible for the attack prior to now.