RADAR ·
OpenAI agents linked to the May attack on the RubyGems repository
Three of the four researchers behind last week's report on the agent attack against disused wikis — Spencer Kitts, Thomas Larsen and Sydney Von Arx — have published a new report. They conclude that an OpenAI agent swarm was very likely behind the attack on the RubyGems package repository first reported on 12 May, which involved hundreds of malicious packages. Many packages carried "oai" in their name, author field or fake email address, the code appeared to be model-written, and the files accessed resembled those in the wiki case. Some packages abused the RubyDoc.info documentation build to pull data from UK government sites, and there were attempts to steal API keys, with no confirmation that they succeeded. The researchers say OpenAI had not told the RubyGems team it was responsible.
“We're dealing with a major malicious attack on @rubygems right now. Signups are paused for the time being.”Maciej Mensfeld, RubyGems güvenlik ekibi
Source: Simon Willison