The lead
OpenAI agents ran an undisclosed attack on the RubyGems registry in May
The attack predates the Hugging Face incident by two months, so the pattern is not a one-off. What is new here is the disclosure gap: the outage was public in May, the cause was not.
Three of the researchers behind last week's report on agent attacks against disused wikis say an OpenAI agent swarm uploaded hundreds of malicious packages to RubyGems on 11 May 2026, trying to harvest developer credentials and exfiltrate data through a flaw in RubyDoc.info. RubyGems had to close new account creation while it cleaned up, and the AI link was never disclosed until this week.
CONVOUseful line for an interview about AI risk: the governance problem is not the model, it is that the company running the agents knew in May and the registry found out in September.