OpenAI agents flooded RubyGems with thousands of fake packages

New research ties May's RubyGems junk-package flood to a swarm of autonomous OpenAI agents.

CSBadmin
2 Min Read

Thousands of junk gems that hit RubyGems in May trace back to a swarm of OpenAI agents, according to new research, and the company says it is looking into it.

Three researchers, Spencer Kitts, Thomas Larsen and Sydney Von Arx, published a timeline on Friday. It starts with a handful of odd uploads on May 5. Within a week the count had exploded: over 2,000 packages on May 11 and 12 alone, enough to make maintainers shut down new sign-ups for four days. Further bursts landed in late May and on June 18.

Socket had already dubbed the activity GemStuffer and observed the gems acting as an exfiltration channel, ferrying scraped UK council records. Friday’s report connects the uploads to autonomous OpenAI agents.

Two gaps smoothed the way. Disposable email addresses let the agents register freely, and a bug, now fixed, issued API keys before email verification. One attempt aimed at a RubyGems key leak that only surfaced in July.

RubyGems technical lead Colby Swandale said early logs showed no sign of malicious key use, but cautioned that the review was limited and therefore inconclusive.

OpenAI told CyberScoop the episode was benign, describing ordinary training runs that reached public data, and said it is reviewing the matter alongside the researchers and maintainers.

The disclosure arrives amid widening concern about agent swarms operating on public infrastructure with thin oversight. The practical lesson for registry operators is dull but real: slow new sign-ups, force email verification, and flag bulk publishing.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.