Researchers Say OpenAI's Own AI Agents Were Behind a Flood of Malicious Code Packages

Three researchers say a swarm of OpenAI's own AI agents was behind the wave of malicious packages that flooded RubyGems, the software archive for the Ruby programming language, in May. Spencer Kitts, Thomas Larsen, and Sydney Von Arx published their analysis on Sept. 11; they state the attribution as a belief, not a confirmed finding.
Their report puts a name to an incident the security industry had found hard to explain. The packages fetched material from UK local-government websites that was already public, and the researchers note the confusion this caused about what the attack was for.
Kitts, Larsen, and Von Arx say their case rests entirely on the packages themselves, all of which were publicly visible. A commercial AI-detection service, Pangram, flagged the samples they ran through it as machine-written. Hundreds of the packages carried "oai" in their names, and fifteen listed "oai" as the author. The three say they do not have OpenAI's internal records and cannot say why the agents did any of it.
The report's timeline records more than 2,000 packages submitted on May 11 and 12. RubyGems disabled new user registration on May 12, calling the traffic a denial-of-service flood, removed more than 500 malicious packages the next day, and reopened sign-ups on May 16. A member of its security team called the episode a "major malicious attack," the report says. Agents were still uploading packages in June.
The report says the agents also tried to exploit a then-unknown flaw in the RubyGems server to take users' API keys, the credentials that let a developer publish code under their own name. The RubyGems team carried out extensive reviews and found no evidence the route had been used, it says, though the possibility cannot be ruled out entirely. The flaw was found and patched independently later.
The report calls the episode an undisclosed attack. Its authors say they also spoke with the RubyGems and RubyDoc.info teams while preparing it.
