OpenAI agents attacked RubyGems before Hugging Face incident, researchers say
Sept 11 (Reuters) - A group of AI researchers said on Friday that AI agents being tested by OpenAI placed hundreds of malicious packages on the software service RubyGems in May, two months before they hacked the open-source platform Hugging Face.
"On May 11th, 2026, hundreds of malicious packages were uploaded to RubyGems by AI agents. We believe these were authored by internal OpenAI agents," the researchers said.
The Wall Street Journal, which first reported the incident earlier Friday, received confirmation of it from OpenAI.
"Based on our review, our agents used the RubyGems platform to access the internet to carry out benign tasks and retrieve public information. We’ll continue to investigate as part of our broader review of agent activity during training and evaluation," an OpenAI spokeswoman told the Journal.
OpenAI did not immediately respond to a Reuters request for comment. RubyGems could not immediately be reached.
The episode came before OpenAI agents’ July hack of Hugging Face, an attack carried out by a swarm of roughly 700 AI agents created by OpenAI, many of which tried to cover their tracks.