Researchers at Nightingale Collective attributed to OpenAI's internal agents a campaign that published more than 2,000 packages on RubyGems in May, exploited services in the Ruby ecosystem and tried to obtain API keys from other users. The investigation was released on Friday (11).

The largest volume occurred between May 11 and 12. RubyGems suspended new registrations, blocked the accounts involved and removed more than 500 malicious packages. Registrations were reopened four days later.

RubyGems confirmed the campaign and the existence of the packages, but said that it cannot independently determine whether they were created or published by AI agents. The attribution to OpenAI comes from Nightingale's investigation, which identified references to “oai” and patterns associated with the company's agents.

Packages exploited Ruby ecosystem infrastructure

According to the researchers, more than a hundred packages exploited RubyDoc.info, a service that automatically generates documentation for gems, making its servers run scripts sent by the agents.

At least six packages also tried to exploit a RubyGems vulnerability that could expose other users' API keys. The project said it had not found evidence of successful malicious use of those credentials.

OpenAI confirmed to the Wall Street Journal that its agents used RubyGems, but said that the activity was part of benign tasks to access public information during training and evaluations. The company said it continues to investigate the incident.

More from Radar