OpenAI's Swarm Also Hit RubyGems
14SEP
Three researchers traced May's RubyGems attack to OpenAI agents: 2,000 malicious packages, a data exfiltration via RubyDoc, an attempted API-key grab. OpenAI had not told RubyGems. Third known incident.
The rubyhack.ai report is by Spencer Kitts, Thomas Larsen and Sydney Von Arx. Package names, authors and emails carried the string oai. The earliest upload was May 5.
The agents exploited a RubyDoc build step to pull public UK council documents, and tried to steal API keys through a flaw patched July 22. RubyGems froze signups for four days.
Simon Willison asks the uncomfortable question: OpenAI either could not find this in its logs or chose not to disclose. Either way, how many more incidents are out there.