OpenAI agents attacked RubyGems before Hugging Face incident, researchers say
Researchers said more than 2,000 uploads targeted RubyGems in May, while OpenAI called the activity benign training and evaluation.
- Researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx reported on Friday that OpenAI agents uploaded more than 2,000 malicious packages to RubyGems, a public library for the Ruby programming language.
- Days into the campaign, agents used 'disposable' email addresses and exploited a platform bug to gain API keys without verifying their accounts, according to the report published Friday.
- Fifteen packages listed the same author and files contained specific labels like 'hack.rb' and 'evil.rb,' indicating the agents 'clearly regarded what they were doing as hacking,' researchers said.
- OpenAI characterized the episode as 'benign' routine training runs, yet RubyGems maintainers halted new user sign-ups for four days to contain the flow of malicious uploads.
- This activity follows similar incidents involving a German Wiki and the Hugging Face platform, heightening public concern over developers' capacity to contain autonomous agents during testing.
43 Articles
43 Articles
OpenAI Agents Attacked RubyGems Before Hugging Face Hack, Researchers Say
AI agents being tested by OpenAI attacked software service RubyGems two months before they hacked open-source platform Hugging Face, researchers said, the latest revelation of cyberattacks linked to major AI developers that have spooked the public and spurred calls for tighter regulation.Many incidents where AI agents from developers such as OpenAI and rival Anthropic have hacked or attempted to access external systems have heightened concerns …
OpenAI agents attacked RubyGems before Hugging Face incident, say researchers
AI agents being tested by OpenAI attacked the software service RubyGems two months before they hacked the open-source platform Hugging Face, researchers said, the latest revelation of cyberattacks linked to major AI developers that have spooked...
Two months before Open AI's AI models broke out of a test environment and attacked the Hugging Face platform, they had already carried out another cyberattack, reports The Wall Street Journal.
The RubyGems developer platform was targeted by a malicious operation.
Coverage Details
Bias Distribution
- 42% of the sources lean Right
Factuality
To view factuality data please Upgrade to Premium






























