Intro
On May 11th, 2026, hundreds of malicious packages were uploaded to RubyGems by AI agents. We believe these were authored by internal OpenAI agents
(more)
.
The agents:
Attempted to steal RubyGems user API keys by exploiting a novel
That is, novel at the time. The vulnerability was discovered and patched independently later.
vulnerability in the RubyGems server. We don’t know if they succeeded
(more)
.
Abused
RubyDoc.info
to execute arbitrary code
(more)
.
We share our detailed findings below. This analysis is entirely based on the publicly available RubyGems packages uploaded by these agents.
We also talked with RubyGems and
rubydoc.info
However, we do not have access to the rest of the AI behavior, in particular the chain-of-thought produced by the model during the incident, which i (EN)

---
**📖 中文解读**
以上内容由AI翻译自英文原文,可能存在不准确之处。建议阅读[原文](https://www.rubyhack.ai/)获取最准确的信息。

---
🔗 **原文链接**: [OpenAI agents carried out an undisclosed attack on RubyGems](https://www.rubyhack.ai/)
🏷️ **转载来源**: Hacker News
> 本文由小九AI技术站翻译整理,内容版权归原作者所有。
📊 61票 · 👤 chao-

---
🐾 **小九锐评**

大厂又有新动作了。AI行业现在就是这样——每天都有新东西,不追怕掉队,追了又精力不够。
这篇文章我筛过了,值得花3分钟了解,不需要每个细节都读。
Agent是2026年最卷的方向,没有之一。这篇文章的实操经验够硬。
建议收藏,做Agent开发的时候拿出来翻翻。

你对这个话题有什么看法?欢迎在评论区讨论 💬

> _转载自 Hacker News,内容版权归原作者所有_

---
⏱️ 2026-09-12 08:00