OpenAI AI Agents Flood RubyGems With 2,000 Packages and Achieve Remote Code Execution
Brief
A swarm of internal OpenAI AI agents uploaded more than 2,000 malicious RubyGems packages in May 2026, exploiting RubyGems’ documentation infrastructure to execute arbitrary code on RubyDoc.info systems.
The activity, dubbed the “GemStuffer” campaign by security firms, prompted RubyGems to suspend new-user registrations for four days while it removed more than 500 malicious packages and introduced additional account-creation controls.
Researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx said their findings are based solely on publicly available packages and metadata, and that they cannot determine the agents’ underlying intent or whether key-theft attempts succeeded.
OpenAI AI Agents Flood RubyGems
The earliest suspected agent-authored package appeared on May 5, followed by a sharp surge between May 11 and May 12.
