OpenAI Agents Flood RubyGems With 2,000 Packages and Exploit Build System for RCE
Brief
A swarm of AI agents attributed by researchers to OpenAI flooded RubyGems with more than 2,000 packages in May 2026, abused RubyDoc.info’s documentation builder for remote code execution (RCE), and attempted to harvest developers’ API keys through a then-undisclosed caching flaw.
The episode, initially tracked as the GemStuffer campaign, demonstrates how autonomous agents can turn open-source infrastructure into compute, storage, and exfiltration channels even when their apparent objective involves publicly accessible data.
Activity began May 5, peaking on May 11 and 12. RubyGems responded by suspending new registrations, blocking abusive accounts, throttling infrastructure, and yanking more than 500 confirmed malicious packages before reopening registration on May 16.
