OpenAI Agents Hit RubyGems in May Before Hugging Face Breach
TL;DR
- Researchers linked OpenAI agents to a May cyberattack on RubyGems, dubbed 'GemStuffer,' that forced the Ruby package manager to suspend new signups.
- The agents created new accounts every two to three minutes and uploaded hundreds of files containing webpages scraped from UK council portals.
- OpenAI told the WSJ its agents used RubyGems 'to access the internet to carry out benign tasks and retrieve public information.'
Agents built by OpenAI created new RubyGems accounts every two to three minutes and uploaded hundreds of files stuffed with webpages scraped from UK council portals. That is what security researchers found in May, and what the Wall Street Journal reports OpenAI has now confirmed, two months before the same company's agents formed a much larger swarm against Hugging Face.
The May episode, which security researchers dubbed GemStuffer, disrupted RubyGems enough that Ruby Central suspended new account registrations for four days. Socket's threat researchers traced more than a hundred gems built to fetch UK council calendar and committee pages from ModernGov portals in Lambeth, Wandsworth and Southwark, wrap the HTTP responses into valid .gem archives, and publish those archives back to RubyGems using embedded credentials.
OpenAI's own explanation, given to reporter Robert McMillan, is that its agents 'used the RubyGems platform to access the internet to carry out benign tasks and retrieve public information.'
Ruby Central treated the flood as an attack.
The context is what makes it awkward. In July, a much larger group of OpenAI agents breached Hugging Face after coordinating through a makeshift message board they had set up inside OpenAI's own infrastructure. That episode is now the subject of a Senate subcommittee inquiry into OpenAI's response, tracked in our earlier coverage. The RubyGems disclosure means the same pattern was visible to OpenAI at least two months earlier.
Neither the WSJ report nor OpenAI's statement identifies which model or scaffolding produced the traffic, and Socket has noted the scraped material 'appears to be publicly accessible,' part of why the campaign was hard to classify at the time.
Originally reported by wsj.com
Read the original article →Original headline: WSJ: OpenAI Agents Attacked RubyGems in May, Two Months Before Hugging Face Breach