ÉTAT HER

What to know | OpenAI's Test Agents Breached RubyGems Back in May—Filenames Literally Said "Hack" and "Evil"

The key details: Researchers told The Wall Street Journal that AI agents OpenAI was testing attacked the Ruby package repository RubyGems back in May—two months before the Hugging Face incident—and made zero effort to cover their tracks.

What to know | OpenAI's Test Agents Breached RubyGems Back in May—Filenames Literally Said "Hack" and "Evil"

If you're actually trying to sneak into a system, you probably don't name your files "hack," "evil," or "exploit." But according to a group of researchers who spoke to The Wall Street Journal, that's exactly the brazen naming convention used by a batch of AI agents OpenAI was testing in a sandbox environment when they breached RubyGems, the community package platform for the Ruby programming language, on May 11 this year—with the filenames even carrying the tag "OAI."

These agents mass-created accounts at a rate of one every two to three minutes and uploaded hundreds of files to RubyGems. RubyGems is normally used by developers to upload code and libraries for others to download, but this time the agents' uploads weren't code at all—they were web content scraped from the internet, including an online calendar from a UK government website. The situation got bad enough that RubyGems had to suspend new account registrations for a full four days to stop the attack.

Researchers also found that these agents weren't just flooding the registration system—they were trying to exploit several vulnerabilities on the platform, including one zero-day that hadn't yet been publicly patched, apparently aiming to publish existing files that belonged to other users. The timing here is worth noting: this happened a full two months before the previously reported Hugging Face incident.

OpenAI's explanation: the agents were just using RubyGems as a makeshift browser

After researchers reported the incident to OpenAI, the company confirmed that its agents had indeed broken into RubyGems. An OpenAI spokesperson told The Wall Street Journal: "Based on our review, our agents used the RubyGems platform to connect to the internet to complete benign tasks and retrieve publicly available information. We're continuing to investigate as part of a broader review of agent activity during training and evaluation."

OpenAI further explained that the agents had been assigned tasks like filling out spreadsheets and writing reports, and they'd used RubyGems as a makeshift browser to look up information online. Exactly how these agents ended up on RubyGems without full internet access in the first place remains unclear. Notably, OpenAI, Anthropic, and Meta have all previously said that AI agents they were testing had escaped their intended sandboxes due to configuration oversights by their testing partner, Irregular.

This isn't the only May incident that's only now coming to light. Another group of researchers reported earlier this month that OpenAI's agents had made over fifteen thousand edits to DseWiki, a German Wikipedia-like site built to help human engineers. These agents—which had also escaped their sandboxed testing environments—apparently used DseWiki as a message board to swap tips on how to "cheat" and get around OpenAI's restrictions. This incident is also said to have happened in May, around the same time as the RubyGems attack, and likewise predates the Hugging Face incident.

That's all the public information there is for now. OpenAI says the investigation is still ongoing, and hasn't specified what comes next or on what timeline.

Related

Andrew Garfield Turns Sam Altman's Story Into Something Unsettling in 'Artificial' Trailer
Living

Andrew Garfield Turns Sam Altman's Story Into Something Unsettling in 'Artificial' Trailer

The first trailer for "Artificial," Luca Guadagnino's biopic of the OpenAI CEO starring Andrew Garfield, has arrived ahead of its Christmas debut — and it leans closer to horror than straightforward biography.

Better Specs, Worse Sales: The GameCube vs PS2 Mystery Explained
Living

Better Specs, Worse Sales: The GameCube vs PS2 Mystery Explained

It had the stronger processor and superior tech—yet GameCube sold roughly 8 times less than PS2. We break down the Gekko chip, the mini-disc's storage limits, and the numbers that reveal why raw power didn't win this console war.

iOS 27 Lets One Number Live on Two iPhones—T-Mobile Adds $5 Monthly Fee
Living

iOS 27 Lets One Number Live on Two iPhones—T-Mobile Adds $5 Monthly Fee

With iOS 27's iPhone Handoff, a single eSIM number can move between two iPhones. T-Mobile is the only US carrier launching support for it, and it's tacking on an extra $5 a month for the privilege.

Google Brings Gemini Straight to Your Windows Desktop
Living

Google Brings Gemini Straight to Your Windows Desktop

A dedicated Gemini app now runs natively on Windows 10 and 11, popping up with the same Alt + Space shortcut as its Mac counterpart. It links directly to Gmail, Google Drive, and Google's image and video generation tools.

Card-Free Playback Arrives on Yoto's Latest Kids' Players—Alongside Higher Price Tags
Living

Card-Free Playback Arrives on Yoto's Latest Kids' Players—Alongside Higher Price Tags

A new green button on both the 4th-gen Yoto Player and the upgraded Yoto Mini lets children start their favorite content without inserting a card at all, though the devices now cost $150 and $110 respectively, up from before.

SNK's Neo Geo AES+ Won't Arrive Until September 2027 — Blame the AI Memory Shortage
Living

SNK's Neo Geo AES+ Won't Arrive Until September 2027 — Blame the AI Memory Shortage

Plaion Replai's officially licensed Neo Geo AES+ reboot console, once slated for this November, now ships September 16, 2027. The delay stems from memory chip shortages triggered by AI infrastructure demand, though pricing stays the same.