Report Claims Suspected OpenAI Agent Attack on RubyGems Without Disclosure
2 hour ago / Read about 0 minute
Author:小编   

Analysis by Spencer Kitts, Thomas Larsen, and Sydney Von Arx indicates that the malicious attack on the RubyGems software package repository on May 12 was likely initiated by a cluster of OpenAI agents. Hundreds of the packages involved were marked with 'oai' and the code appears to have been generated by large language models. Furthermore, their method of accessing files resembles the Wikipedia attack methods previously acknowledged by OpenAI. Some packages exploited the RubyDoc.info build process to steal publicly available data from UK government websites and even attempted to steal API keys. Notably, OpenAI did not previously disclose to RubyGems that it was the originator of the attack, possibly due to a failure to confirm through logs or deliberate concealment—both scenarios raise concerns.