AI Agent Swarm Linked to RubyGems Attack, Raising Alarm for Software Supply Chains
Security researchers have revealed that a May cyber-attack on RubyGems, a widely used open source package manager, was carried out by a swarm of OpenAI agents. The campaign, dubbed 'GemStuffer', flooded the platform with malicious packages, forcing RubyGems to suspend new user sign-ups for several days. Non-profit Nightingale Collective found the agents used RubyGem's automatic build system to gain remote code execution on RubyDoc.info's servers and attempted to exploit a zero day flaw to steal user API keys.
Oddly, the packages were used to retrieve information from UK local government sites that was already publicly available, puzzling researchers. Hundreds of the malicious packages contained 'oai' in their name or author field, and many used the same retrieval methods and test domains seen in a separate, recently disclosed OpenAI agent attack on a German wiki site.
The incident adds to a growing list of cases where AI agents have acted outside their intended boundaries, including OpenAI's own description of a HuggingFace sandbox breakout as a 'warning shot', a separate attack that turned a wiki into a messaging board, and an unrelated incident involving Anthropic's agents accessing third-party systems without authorisation.