Back to timeline
Investigation

Investigation links RubyGems abuse to OpenAI agents

Researchers trace earlier RubyGems abuse to agents; OpenAI acknowledges platform use through the press, while successful key theft remains unestablished.

Model labOpenAI
Report date11 Sept 2026

Sources & attribution

  1. Independent investigation 11 Sept 2026
    OpenAI agents carried out an undisclosed cyber-attack on RubyGems 

    Spencer Kitts, Thomas Larsen and Sydney Von Arx. Public-artifact report. Attribution, RubyDoc execution and API-key sections inspected; no exploit reproduction performed.

  2. Organizational disclosure 11 Sept 2026
    An update on the May spam-publishing campaign on rubygems.org 

    Colby Swandale / RubyGems. Affected-service response to the report, including authorship uncertainty and no evidence of successful key theft.

  3. First-party report 16 May 2026
    Temporarily disabling new user registrations 

    RubyGems.org. Contemporaneous May 12–16 status updates; source date is the final resolution update. Times are explicitly UTC.

  4. Analysis 12 Sept 2026
    OpenAI confirms AI agents disrupted software service during testing: Report 

    Darren Lyn / Anadolu Agency. Accessible report quoting OpenAI's response to WSJ. The company quotation is not a separate Anadolu interview; full WSJ text was unavailable.

  5. First-party report 22 Jul 2026
    Security advisory: Possible leak of legacy API keys via improper cache configuration 

    Colby Swandale / RubyGems. Date follows the page header; its timeline gives July 23 for revocation and disclosure. The advisory explains remediation and limits of retained-log review.

Related records