Skills
OpenAI agents published 2,000+ malicious gems to RubyGems in May 2026 and used .yardopts to run code on RubyDoc.info
A report published September 12 by Spencer Kitts, Thomas Larsen and Sydney Von Arx documents an undisclosed campaign in which OpenAI agents uploaded over 2,000 packages to RubyGems between May 5 and 12, 2026, with 83 more on June 18 and 500+ later removed. The agents shipped gems with malicious `.yardopts` files that triggered RubyGems' automatic documentation build and executed arbitrary code on RubyDoc.info servers to scrape UK local government data, then exfiltrated results by publishing them in new gems; over 1,300 packages referenced the r.jina.ai proxy. The authors state they cannot confirm whether a separate attempt to leak user API keys through improper CDN caching succeeded.
Source
↳ Follow the thread