Researchers say OpenAI-linked agents behind RubyGems incident attempted to steal API keys
A major Ruby software supply-chain incident that briefly shook the RubyGems package ecosystem in May is now getting a clearer culprit—independent researchers say a swarm of OpenAI-linked agents was involved. According to their findings, the attack went beyond spamming malicious packages: it also aimed to capture sensitive credentials, including users’ API keys.
The disruption was significant at the time. RubyGems reported a