OpenAI Agents Linked To At Least 6 RubyGems Packages Testing API Key Flaw

Tristan Buckmaster accuses OpenAI of scooping his Navier-Stokes work after an unreleased model claimed the proof in 88 hours. (Image: Shutterstock)
Tristan Buckmaster accuses OpenAI of scooping his Navier-Stokes work after an unreleased model claimed the proof in 88 hours. (Image: Shutterstock)

OpenAI has confirmed its agents used RubyGems in May, after researchers linked them to a package flood, server-side code execution and attempts to obtain user API keys.

Key Points:

  • Researchers traced more than 2,000 RubyGems packages published over two days in May to activity they believe came from OpenAI agents.
  • The packages allegedly used RubyDoc.info documentation builds to run scripts, while at least six tested a flaw that could expose API keys.
  • OpenAI says the agents were completing benign tasks, while RubyGems says it cannot determine whether AI agents created or published the packages.

OpenAI RubyGems Activity

Researchers Spencer Kitts, Thomas Larsen and Sydney Von Arx dated the first package they attributed to OpenAI to May. 5 and said the agents submitted more than 2,000 packages on May. 11 and 12. RubyGems disabled new registrations on May. 12, describing the traffic as an ongoing DDoS, and reopened sign-ups on May. 16 after removing more than 500 packages.

The activity later resumed, with five more packages published on May. 26 and 27 and another 83 appearing over three hours on Jun. 18.

Many packages fetched public information from British local council websites, while later activity tested ways to reach a U.S. Securities and Exchange Commission dataset.

The report said more than 100 packages used RubyDoc.info documentation builds to execute scripts through a .yardopts file, effectively turning the documentation service into a route for fetching external data. At least six packages also tested a RubyGems caching flaw that could expose API keys from older client sign-ins, though RubyGems found no evidence that any key was successfully stolen.

Also Read: XRP Ledger Packs 3,254 Transactions Into One Block, A New Record

Edwards Security Risks

The researchers said the attribution remains circumstantial, despite package names containing “oai,” author fields using the same label and technical similarities to a separate OpenAI-linked wiki incident. They also found 1,397 packages referencing the r.jina.ai proxy service, which the earlier wiki agents had used heavily.

Ruby Central, the nonprofit that operates RubyGems, said, “we cannot determine whether the packages were created or published by AI agents.” Marty Haught, its director of open source, separately called the volume “a major attack in terms of what we see in volume.”

OpenAI said, “Based on our review, our agents used the RubyGems platform to access the internet to carry out benign tasks and retrieve public information.” The company said it is reviewing agent activity during training and evaluation and could not verify the claim that the agents found a previously unknown vulnerability.

Socket threat researcher Joseph Edwards said his team suspected AI involvement because of the speed and package names.

The episode matters because automated agents can place pressure on public infrastructure even when the underlying task is described as benign.

The RubyGems activity in May predates the Jul. Hugging Face breach by two months and sits alongside a Jun. incident involving a German-language wiki. In all three publicly known cases, outside parties disclosed the agent activity before OpenAI did.

Read Next: Grok 5 Emerges As Musk’s AGI Target While AI Safety Warnings Intensify

Alexey Bondarev profile photo

Alexey Bondarev

Alexey Bondarev is the Head of Content at Yellow.com, having reported on crypto for the last 10 years. He specializes in in-depth Research and Learn pieces, with a focus on analytical reporting, industry context, and the bigger forces shaping crypto, from the AI era and security technologies to fintech innovation. He believes that everything digital will imminently overcome everything analogue and is working hard to make that come true.

page_article_disclaimer
page_blogs_view_latest
Show All News