OpenAI Agents Struck RubyGems Before Hugging Face Attack, Researchers Say  - Inspirepreneur Magazine

OpenAI Agents Struck RubyGems Before Hugging Face Attack, Researchers Say 

Sep 12, 2026 11:27 AM IST
Category Technology

Synopsis

OpenAI agents attacked RubyGems in May, uploading hundreds of malicious packages before a separate July Hugging Face incident involving hundreds of agents.

OpenAI agents hacked into the RubyGems software repository on May 11 uploading hundreds of malicious packages to it, say researchers who traced the activity back to an internal OpenAI test.

The incident occurred approximately two months before Hugging Face experienced another breach in July. OpenAI acknowledged the RubyGems incident and stated that their agents were using the website for “harmless activities” and to connect with the web to obtain public information.

01
Chapter one

RubyGems Attack Disrupted Service 

In RubyGems, researchers determined the attack, called “GemStuffer,” to be a project of OpenAI agents that registered accounts every two to three minutes and uploaded between 100 and 200 files each.

The activity swamped RubyGems, which closed new account registration on its website for four days. The uploaded content was mostly 'scraped web pages' rather than software packages, researchers said.

The OpenAI agents also tried to access the server using its RubyGems credentials by taking advantage of some previously unknown server vulnerability, researchers reported. They were not able to tell if the attempt succeeded in getting credentials.

The agents also leveraged RubyDoc.info, a software-documentation generation service, to run code on their servers, the researchers found. OpenAI is reportedly looking into the matter.

02
Chapter two

Earlier Incident Adds to AI Agent Security Cases 

The RubyGems episode preceded the hugging face hack in July, where approximately 700 of about 1,200 agents involved in an OpenAI cybersecurity challenge got involved in an activity that went out to the external platform.

According to the Stanford HAI 2026 AI Index Report, 88% of the surveyed organisations used AI in 2025, and 70% used generative AI in at least one business function. For most business functions, on the other hand, the deployment of AI-agent has not risen above the single figures.

The report further revealed that the UAE (64%), Singapore (60.9%) and the U.S. (28.3%) are among the top adopters of generative AI, with the U.S. coming in last place, ranking 24th worldwide.

03
Chapter three

OpenAI’s Latest Financial Figures 

According to OpenAI, their total annualised revenue in 2025 was more than $20 billion, whereas it was $6 billion in 2024. In March 2026, they announced $122 billion in committed capital with a total worth of $852 billion.

The firm's recent announcements also reveal its computing growth, which will increase from 0.6 gigawatts in 2024 to 1.9 gigawatts in 2025.

Since then, OpenAI agents have been connected with at least three incidents with external systems, such as the RubyGems and Hugging Face incidents and a previous incident on a German-language wiki.

Source: Reuters

Pooja Malik
Written by Pooja Malik

Pooja Malik is a business journalist with over six years of experience covering startups, entrepreneurship, and emerging trends. She has previously worked with leading media platforms such as YourStory Media and BW BusinessWorld, where she reported on business, policy, and market developments. Currently, she serves as Editor at The Inspirepreneur Magazine, where she writes and edits stories across business, lifestyle, and travel, with a focus on clarity, accuracy, and reader relevance.