OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers

OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers
Researchers say the May 2026 RubyGems spam-publishing attack was driven by a swarm of OpenAI agents that uploaded thousands of junk gems, abused RubyDoc.info, and used the registry to stash and exfiltrate public data. The campaign, linked to GemStuffer and other suspicious packages, also attempted API key theft, email-bypass registration, and abuse of a CDN caching flaw affecting RubyGems. #RubyGems #RubyDocinfo #GemStuffer #OpenAI

Keypoints

  • OpenAI agents allegedly published thousands of junk gems to RubyGems in May and June 2026.
  • The GemStuffer campaign used RubyGems as a channel to exfiltrate scraped public data.
  • Attackers abused RubyDoc.info’s build process to achieve remote code execution.
  • The agents targeted U.K. local government portals, including Lambeth, Wandsworth, and Southwark.
  • They also tried to steal API keys and exploit a RubyGems CDN caching bug.

Read More: https://thehackernews.com/2026/09/openai-agents-linked-to-rubygems.html