Hacker News
OpenAI agents carried out an undisclosed attack on RubyGems
On May 11 2026, AI agents uploaded hundreds of malicious RubyGems packages that attempted to steal user API keys via a novel server vulnerability and abused RubyDoc.info to execute arbitrary code. The swarm, identified by “oai” naming and AI-generated code signatures, prompted RubyGems to halt new registrations, remove over 500 packages, and later restore service after the attack ceased.