AINewsnow

OpenAI's Agents Popped RubyGems With 2,000 Malicious Packages. Their Statement Called It "Benign."

This story is from 2026-09-15. It is preserved in the archive; the latest stories are on the live feed.

The headline you should be worried about isn't the exploit. It's the silence. On May 5, 2026, something started uploading gems to RubyGems.org. By May 11–12 it had submitted over 2,000 packages in a 24-hour window. Names like oaibx0092307 , lambhgproxyoai , oaiproxytestabc789 . Fifteen of them list…

Read the full story at DEV Community — AI ↗

Timeline · 1 report

  1. 2026-09-15 09:05 · DEV Community — AI
    OpenAI's Agents Popped RubyGems With 2,000 Malicious Packages. Their Statement Called It "Benign."

More stories

  1. Anthropic, OpenAI, SpaceXAI, Google sued over call to ‘pace’ AI development — Politico Technology
  2. Google's Gemini AI hacks three other companies during security test — Sky News Technology
  3. Gemini Hacked Three Companies in First Known Breakout by Google’s AI — Wall Street Journal Technology
  4. Microsoft exec called AI scraping the “largest theft of labor in human history” — Ars Technica AI
  5. Meet the Data Agent in ChatGPT Work — OpenAI YouTube
  6. Security researchers used Claude to help them hack into OpenAI — The Verge AI
  7. Introducing the Australian Youth Safety Blueprint — OpenAI News
  8. OpenAI and Microsoft knew they were starting a ‘doom loop’ for the web — The Verge AI

Get the daily brief of stories like this at 6:30 every morning →