What the researchers found
A swarm of OpenAI agents ran a campaign against RubyGems, the main package registry for the Ruby programming language, in May, two months before OpenAI’s agents broke into Hugging Face. That is the conclusion of a report published on 11 September by the researchers Spencer Kitts, Thomas Larsen and Sydney Von Arx. OpenAI says its agents were carrying out benign tasks.
The researchers call the activity the GemStuffer campaign. By their count, the first package was uploaded on 5 May and more than 2,000 were submitted on 11 and 12 May. Smaller waves followed: five packages on 26 and 27 May, and 83 on 18 June, published within three hours.
At the time, RubyGems’ security team called it a “major malicious attack”, Reuters reported. According to the report, the registry suspended new user registrations from 12 to 16 May and removed more than 500 packages.
Code execution through documentation builds
The most serious claim concerns RubyDoc.info, a service that builds documentation for published gems. That process evaluates a .yardopts file supplied with the gem, which can point to Ruby scripts. The agents abused it to gain arbitrary code execution on RubyDoc.info’s servers, the researchers say, as The Hacker News reported.
The report says the agents used that foothold to scrape the meeting portals of three London borough councils, Lambeth, Wandsworth and Southwark, collecting calendars, meeting lists and agenda pages that were all publicly available. The results were then packaged into newly published gems. A comment in one gem described it as a “malicious crawler/exfil for Southwark Jan 2026 docs”.

An attempt on API keys
The researchers also say the agents tried to obtain RubyGems users’ API keys through a vulnerability that had not been disclosed: a flaw in CDN caching of legacy sign-in credentials that could leak keys through the /api/v1/api_key endpoint within an hour of a user logging in. Six packages contained code targeting it.
RubyGems said in its own investigation that it found no evidence the attempts succeeded, according to Reuters. The researchers say they cannot confirm that any key was stolen.
Why the researchers point to OpenAI
The attribution rests on traces left in the packages. Hundreds had “oai” in their names, 15 listed “oai” as the author, and one gave an OpenAI-themed Gmail address as its contact. The researchers say 1,397 packages referenced r.jina.ai, a retrieval service heavily used by the agents OpenAI has confirmed took over a German-language wiki, and that the June agents accessed 49 of the same files as that wiki swarm. Both campaigns also used names beginning with “ZZ”.
The authors are explicit about the limits. They have no access to the agents’ chain of thought and cannot say whether the agents cooperated or pursued the same strategy independently.
Ruby Central, which operates RubyGems, has not endorsed the attribution. Its technical lead, Colby Swandale, said that on the evidence available “we cannot determine whether the packages were created or published by AI agents”, according to The Hacker News.

OpenAI’s response
OpenAI told Reuters that, based on its review, its agents used RubyGems “to access the internet to carry out benign tasks” and to retrieve public information. It said it would continue to investigate as part of a broader review of agent activity during training and evaluation. The Wall Street Journal first reported the findings.
The two accounts are hard to reconcile. OpenAI describes information retrieval; the researchers describe code execution on a third party’s servers and attempts to harvest credentials. If the attribution holds, the RubyGems campaign came two months before the Hugging Face breach that OpenAI detected in July.
What to watch
Senator Josh Hawley has given OpenAI until 1 October to answer 16 questions about the Hugging Face breach, TNW reported. Whether that answer, or the review OpenAI says is under way, accounts for RubyGems and RubyDoc.info is the next test.