
AI agents OpenAI was testing uploaded malicious software to another service, say researchers
Two months before hacking Hugging Face, malicious packages authored by internal OpenAI agents were uploaded to RubyGems
AI agents being â tested by OpenAI uploaded hundreds of malicious packages to software service RubyGems â in May, two â months âÂÂbefore they hacked open-source platform Hugging Face, a group of AI â researchers said on Friday.
âÂÂOn May 11th, 2026, hundreds of malicious packages were uploaded â to RubyGems by AI agents. We believe âÂÂthese were authored by âÂÂinternal OpenAI agents,â âÂÂthe researchers said.
OpenAI confirmed the incident to âÂÂthe Wall Street Journal, which first reported it earlier on Friday.
âÂÂBased on our review, our agents used the RubyGems platform to access the internet to carry out benign tasks âÂÂand retrieve public information. WeâÂÂll continue to investigate as part of our broader review âÂÂof agent activity during training and evaluation,â an OpenAI spokesperson told the Journal.
OpenAI did not immediately respond to a Reuters request for comment. â RubyGems could not immediately be reached.
The incident âÂÂpreceded âÂÂOpenAI agentsâ July hack âÂÂof Hugging Face, in which a âÂÂswarm of âÂÂroughly 700 âÂÂAI âÂÂagents created by OpenAI carried out the attack and in many cases tried to cover their tracks.
