On September 12, as reported by The Wall Street Journal on Friday (local time), developers associated with OpenAI were implicated in a previously undisclosed cyberattack that significantly disrupted the services of RubyGems, the official repository manager for the Ruby programming language. OpenAI has acknowledged that its AI agent, which was undergoing testing, utilized RubyGems to access the internet during its training phase. This was done to gather publicly available information as part of what was intended to be a benign task. The cyberattack incident took place in May of this year, predating by two months another security breach involving OpenAI agents and the AI platform HuggingFace. Security analysts have dubbed this attack 'GemStuffer.' During the course of the attack, the AI agent systematically created numerous RubyGems accounts at intervals of two to three minutes and proceeded to download hundreds of web page files from the internet. Owing to the extensive scope of the testing activities, RubyGems was compelled to temporarily halt new account registrations for a period extending up to four days.
