
Two months before hacking Hugging Face, malicious packages authored by internal OpenAI agents were uploaded to RubyGems
AI agents being tested by OpenAI uploaded hundreds of malicious packages to software service RubyGems in May, two months before they hacked open-source platform Hugging Face, a group of AI researchers said on Friday.
“On May 11th, 2026, hundreds of malicious packages were uploaded to RubyGems by AI agents. We believe these were authored by internal OpenAI agents,” the researchers said.
Continue reading…





