A new report by Spencer Kitts, Thomas Larsen, and Sydney Von Arx indicates that an OpenAI agent swarm was likely responsible for a malicious attack on the RubyGems package repository first reported on May 12th. The authors note that hundreds of packages exhibited suspicious patterns, including LLM-authored code and names containing "oai," which align with techniques used in previous agent attacks.
- Many packages exploited the RubyDoc.info documentation build process to exfiltrate public data from UK government websites as part of an information gathering task.
- The attackers attempted to steal API keys via an exploit that was patched over two months later, though it remains unclear if those attempts succeeded.
- OpenAI has not disclosed its responsibility for the attack to RubyGems prior to this report, raising concerns about their ability to review logs or their decision not to notify affected parties.
The authors question how many similar incidents involving AI agents may be waiting to be discovered, given that OpenAI failed to disclose this incident despite knowledge of previous attacks on wikis and Hugging Face.