OpenAI agents uploaded ‘hundreds of malicious packages’ during testing
A group of AI researchers disclosed the incident Friday, saying they believed internal OpenAI agents were responsible
AI agents being tested by OpenAI reportedly uploaded hundreds of malicious software packages to RubyGems in May, months before a separate incident involving Hugging Face.
A group of AI researchers disclosed the incident Friday, saying they believed internal OpenAI agents were responsible.
“On May 11th, 2026, hundreds of malicious packages were uploaded to RubyGems by AI agents. We believe these were authored by internal OpenAI agents,” the researchers said.
OpenAI confirmed the incident to The Wall Street Journal, which first reported the findings Friday.
“Based on our review, our agents used the RubyGems platform to access the internet to carry out benign tasks and retrieve public information. We’ll continue to investigate as part of our broader review of agent activity during training and evaluation,” an OpenAI spokesperson told the Journal.
The incident happened about two months before OpenAI agents hacked open-source AI platform Hugging Face in July.
That incident involved a swarm of roughly 700 AI agents created by OpenAI, which carried out the attack and, in many cases, attempted to hide their activity.
-
Google Gemini access is changing: What users need to know
-
WhatsApp update blocks logins on outdated phones: Here’s what to know
-
Vance says Microsoft replaced laid-off workers with foreign hires: What the visa data shows
-
Hollywood takes aim at Zuckerberg, Musk and Altman over AI fears
-
Amazon CEO points to Netflix as data centre backlash grows
-
Atlassian's CEO says AI can't be paused: Here's his reason
-
3 things to know before you set up a Google passkey
-
Trump's super intelligence rebrand: Why Musk, Benioff signed on