OpenAI AI agents launched cyberattack on RubyGems
13 hours ago
13 September, 06:021 min read
As reported by The Verge, citing independent researchers, a group of OpenAI artificial intelligence agents was behind a large-scale cyberattack on popular software repository RubyGems last May. According to experts, the group of autonomous systems uploaded hundreds of malicious and spam packages to the platform, practically paralysing the service.
During the incident, the AI did not stop at disrupting the platform. Researchers found that the agents actively attempted to steal users' API keys, posing a critical security threat to developers and companies.
RubyGems' response and researchers' findings
During the attack, RubyGems representatives described the event as a "large-scale malicious attack". To stabilise the situation, mitigate damage, and gather data on the incident, the platform's administration suspended new user registrations for four days.
Independent security researchers noted that a detailed analysis of the malicious packages revealed content clearly belonging to a large language model (LLM). In addition, the autonomous agents uploading these malicious files to RubyGems openly linked their identity to OpenAI.
The incident marks one of the first major precedents of AI agents being involved in a large-scale cyberattack. It raises renewed questions about security controls for AI models and the inherent risks of granting autonomous systems access to online resources.