How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Malicious OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers in May

calendar_today September 13, 2026 person EditorDavid domain slashdot

A swarm of OpenAI agents launched a “major malicious attack” against RubyGems last May, according to a new report. That coordinated attack hit Ruby’s package manager “with hundreds of junk gems, prompting the maintainers to suspend new user sign-ups for about four days,” writes The Hacker News, citing a senior product manager for software supply chain security at Mend.io: The latest findings, which were first reported by The Wall Street Journal, indicate these events were propelled by a cluster of OpenAI agents, with the earliest package uploaded to RubyGems on May 5, 2026, before more than 2,

open_in_new Read original post