---
title: "OpenAI’s AI Agents Went After RubyGems Before the Hugging Face Hack — 500+ Malicious Packages Were Removed"
type: "News"
locale: "en"
url: "https://longbridge.com/en/news/298788120.md"
description: "Research by the Nightingale Collective reveals that OpenAI's AI agents attacked RubyGems in May, uploading over 500 malicious packages to exploit vulnerabilities and retrieve public information. This incident occurred months before OpenAI disclosed a separate breach of Hugging Face infrastructure in July. While RubyGems removed the packages and found no evidence of successful data theft, OpenAI maintains the tasks were benign. The events have intensified political scrutiny and calls for stricter AI regulation from lawmakers."
datetime: "2026-09-12T02:35:05.000Z"
locales:
  - [zh-CN](https://longbridge.com/zh-CN/news/298788120.md)
  - [en](https://longbridge.com/en/news/298788120.md)
  - [zh-HK](https://longbridge.com/zh-HK/news/298788120.md)
generator: "portal-rs"
---

# OpenAI’s AI Agents Went After RubyGems Before the Hugging Face Hack — 500+ Malicious Packages Were Removed

AI agents from **OpenAI** attacked a software service called **RubyGems** in May, according to research published by the **Nightingale Collective**, months before the hack on Hugging Face.

## What Really Happened at RubyGems

Researchers said that AI agents uploaded hundreds of ​malicious packages to RubyGems and these were used to retrieve information from U.K. local government sites.

They said the AI agents attempted to steal RubyGems user API keys by exploiting a novel vulnerability in the RubyGems server but added that they do not know if the agents succeeded.

In addition, the agents also exploited RubyDoc.info to execute arbitrary code.

“We believe that this incident was the result of an OpenAI agent swarm,” said the researchers.

RubyGems stated on Friday that in May, they temporarily paused new account registrations and blocked and removed the responsible accounts.

The company added that they removed more than “500 malicious packages.” The firm also said that their probe found no proof that these attempts succeeded.

An OpenAI spokesperson said in an emailed statement to Benzinga that, “Based on our review, our agents used the RubyGems platform to access the internet to carry out benign tasks and retrieve public information.”

The spokesperson noted that it will continue to probe as part of a larger evaluation ⁠of agent activity during training and evaluation.

 **Read Also: Bernie Sanders Slams Big Tech as AI Industry Spends $300 Million to Crush Tougher Regulation — ‘81% of Americans’ Say Congress Isn’t Doing Enough** 

## AI Agents Hack and Public Scrutiny

In July, OpenAI disclosed that an autonomous AI agent escaped a controlled testing environment during an internal security evaluation, gained internet access, and breached Hugging Face’s infrastructure.

The incident drew widespread concerns over the cybersecurity risks posed by AI systems. Rep. **Greg Casar** (D-Texas) had said at the time that the incident was “alarming” and urged mandatory independent AI safety testing.

The criticism has not died down since then. Sen. **Josh Hawley** (R-Mo.) accused OpenAI this week of continuing cybersecurity evaluations despite signs that its AI agents were operating outside intended boundaries, demanding records from CEO **Sam Altman**.

Earlier this week, **Anthropic** disclosed a new threat intelligence report on malicious activity involving its Claude models between December 2025 and August 2026.

The report documents cases involving suspected state-sponsored groups, financially motivated criminals, commercial surveillance vendors and political operators.

Sen. **Bernie Sanders** (I-Vt.) is also escalating his push for tougher AI regulation after AI pioneer Geoffrey Hinton talked about the possibility of superintelligent AI killing humanity.

 **See More: Top Value Stocks** 

Image via Shutterstock

### Related Stocks

- [OpenAI.NA](https://longbridge.com/en/quote/OpenAI.NA.md)

## Related News & Research

- [OpenAI faces Senate probe into Hugging Face incident](https://longbridge.com/en/news/298570440.md)
- [OpenAI just wants to win](https://longbridge.com/en/news/298806233.md)
- [OpenAI's Altman won't do IPO this year, calls AI extinction risk 'unacceptable'](https://longbridge.com/en/news/298851266.md)
- [OpenAI investors have approached the company about a new funding round](https://longbridge.com/en/news/299190671.md)
- [Sam Altman Backs Controlling Pace of Frontier AI Development, OpenAI to Introduce Independent Safety Assessments](https://longbridge.com/en/news/298910908.md)

---
> **Disclaimer: This article is for reference only and does not constitute any investment advice.**