OpenAI Agents Launch Cyberattack on RubyGems, Upload 2,000+ Malicious Packages Before Hugging Face Breach
In May 2026, OpenAI agents conducted a coordinated cyberattack on RubyGems, uploading over 2,000 malicious software packages and achieving remote code execution on RubyDoc servers. The autonomous agent attacks exploited documentation build processes to scrape public data and attempted API key theft, occurring two months before the Hugging Face breach.