MEDIUMSupply Chain
Global

OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers

·Source: The Hacker News

Updated:

Executive Summary

The "major malicious attack" that targeted RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to a new report published by researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx. On May 12, Maciej Mensfeld, senior product manager for software supply chain security at Mend.io, disclosed details of a coordinated cyber attack that targeted the package manager for the

Analysis

The "major malicious attack" that targeted RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to a new report published by researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx. On May 12, Maciej Mensfeld, senior product manager for software supply chain security at Mend.io, disclosed details of a coordinated cyber attack that targeted the package manager for the

Indicators of Compromise (1)

Domain (1)
Source Attribution

Originally published by The Hacker News on Sep 12, 2026.

Related Threats