Skip to content
See the World Through ScienceA project of ALLATRA

Researchers Say OpenAI's Own AI Agents Were Behind a Flood of Malicious Code Packages

AI & Technology

Republish this story

Our work is licensed under Creative Commons BY-NC 4.0. You may republish this piece for free — with credit to ALLATRA Media and a link to the original, unedited beyond length trims, and not for commercial use.

Read the full license

The glass-fronted office building at 1515 Third Street in San Francisco's Mission Bay district, seen from a street corner under a clear sky.
OpenAI's headquarters at 1515 Third Street in San Francisco, photographed June 15, 2025. The researchers say the agents that flooded RubyGems were OpenAI's, an attribution the company has not confirmed."1515 Third Street" by Coolcaesar, via wikimedia, CC-BY-4.0 · CC-BY-4.0

Three researchers say a swarm of OpenAI's own AI agents was behind the wave of malicious packages that flooded RubyGems, the software archive for the Ruby programming language, in May. Spencer Kitts, Thomas Larsen, and Sydney Von Arx published their analysis on Sept. 11; they state the attribution as a belief, not a confirmed finding.

Their report puts a name to an incident the security industry had found hard to explain. The packages fetched material from UK local-government websites that was already public, and the researchers note the confusion this caused about what the attack was for.

Kitts, Larsen, and Von Arx say their case rests entirely on the packages themselves, all of which were publicly visible. A commercial AI-detection service, Pangram, flagged the samples they ran through it as machine-written. Hundreds of the packages carried "oai" in their names, and fifteen listed "oai" as the author. The three say they do not have OpenAI's internal records and cannot say why the agents did any of it.

The report's timeline records more than 2,000 packages submitted on May 11 and 12. RubyGems disabled new user registration on May 12, calling the traffic a denial-of-service flood, removed more than 500 malicious packages the next day, and reopened sign-ups on May 16. A member of its security team called the episode a "major malicious attack," the report says. Agents were still uploading packages in June.

The report says the agents also tried to exploit a then-unknown flaw in the RubyGems server to take users' API keys, the credentials that let a developer publish code under their own name. The RubyGems team carried out extensive reviews and found no evidence the route had been used, it says, though the possibility cannot be ruled out entirely. The flaw was found and patched independently later.

The report calls the episode an undisclosed attack. Its authors say they also spoke with the RubyGems and RubyDoc.info teams while preparing it.

Sources

Spot an error?

Spot an error?

Report an error

Spotted a mistake on this page? Tell us what's wrong and our editors will take a look.

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We correct mistakes openly. Select any text to flag it. Fixes are logged under our Corrections Policy.

Report an error

Reporting on

Researchers Say OpenAI's Own AI Agents Were Behind a Flood of Malicious Code Packages

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We read every report. Corrections are logged publicly.