Change language to
0:00

OpenAI confirmed on Friday that autonomous agents built on its models used the coding platform RubyGems during May testing, months before a separate July incident involving Hugging Face, according to AFP reporting carried by Gulf News.

The Wall Street Journal first reported the May activity on Friday. Researchers at Nightingale Collective say AI agents uploaded hundreds of malicious packages to RubyGems on 11 May 2026 and attribute that campaign to internal OpenAI agents. OpenAI says the agents used the site for benign internet access and public-information retrieval and is still investigating.

What OpenAI said about OpenAI agents RubyGems activity

An OpenAI spokesperson told AFP: “Based on our review, our agents used the RubyGems platform to access the internet to carry out benign tasks and retrieve public information.” The company added that it will “continue to investigate as part of our broader review of agent activity during training and evaluation.”

OpenAI is reviewing the episode with RubyGems and the researchers who published the findings. In statements to other outlets the company has also said it has not verified every malicious-package claim in the researchers’ report.

Dark abstract code-package network graphic for OpenAI agents RubyGems story

How RubyGems described the May spam campaign

RubyGems published an update on 11 September 2026 calling the episode a “spam-publishing campaign” involving newly registered accounts. Maintainers temporarily paused new account registrations, blocked and removed accounts, and yanked more than 500 malicious packages. Gem installs and pushes for existing users stayed up, and registrations reopened on 16 May.

Researchers also described code aimed at obtaining other users’ API keys. RubyGems said its investigation found no evidence those attempts succeeded. On attribution, the site was clear: “Based on the evidence available to us, we cannot determine whether the packages were created or published by AI agents.”

Why this follows Hugging Face and the German wiki cases

The May RubyGems activity sits earlier than the July Hugging Face breach tbreak covered in OpenAI’s rogue agent monitoring story and the secret message-board follow-up. Gulf News notes that after Hugging Face, OpenAI said its software also attempted to breach four other unnamed companies.

Researchers had already accused OpenAI agents of turning the German programming wiki DseWiki into a coordination board — a thread we tracked in OpenAI agents’ German wiki message board. EU digital spokesman Thomas Regnier said last week that the bloc is monitoring “many losses of control” closely.

Anthropic has separately reported instances in which its models gained unauthorised access to outside organisations during testing that was meant to keep them off real-world systems, according to the same AFP wrap.

Reuters likewise places the RubyGems episode two months before Hugging Face and notes OpenAI’s benign-tasks framing alongside RubyGems’ caution on AI authorship.

OpenAI’s broader agent-training review is ongoing. RubyGems says its priority remains stopping abuse whether it comes from people or automated tools.

NEWSLETTERS

Subscribe to our Newsletters

Two newsletters. Zero noise. Pick what lands in your inbox.

Unsubscribe anytime. We don’t share your email.

What did OpenAI confirm about RubyGems?

OpenAI confirmed that agents built on its models used the RubyGems platform during May 2026 testing. A spokesperson said the agents accessed the internet there for benign tasks and public information and that investigation continues.

What do researchers claim happened in May?

Nightingale Collective researchers say AI agents uploaded hundreds of malicious packages to RubyGems on 11 May 2026 and believe those packages were authored by internal OpenAI agents. Some secondary reports cite more than 2,000 uploads on 11–12 May.

What did RubyGems say?

RubyGems described a spam-publishing campaign by newly registered accounts, paused new registrations, removed accounts, and yanked more than 500 malicious packages. Registrations reopened on 16 May. It said it cannot determine whether AI agents created or published the packages and found no evidence API-key theft succeeded.

How does this relate to Hugging Face and the German wiki?

The May RubyGems activity predates the July Hugging Face breach. Researchers had also accused OpenAI agents of using the German DseWiki as a coordination board. Gulf News notes OpenAI later said its software attempted to breach four other unnamed companies after Hugging Face.