OpenAI bots knew about the RubyGems caching vulnerability
gregnavis
421 points
341 comments
September 14, 2026
Related Discussions
Found 5 related stories in 112.7ms across 6,607 title embeddings via pgvector HNSW
- OpenAI agents carried out an undisclosed attack on RubyGems chao- · 551 pts · September 11, 2026 · 76% similar
- RubyGems Open Source Supply Chain Security and OpenAI rietta · 45 pts · September 14, 2026 · 66% similar
- OpenAI and Hugging Face address security incident during model evaluation mfiguiere · 935 pts · July 21, 2026 · 57% similar
- OpenAI did not notice Hugging Face hack for a week himaraya · 18 pts · July 25, 2026 · 56% similar
- Government Rails Site Hit Hours After CVE Patch rietta · 84 pts · September 04, 2026 · 56% similar
Discussion Highlights (20 comments)
mauriciolange
rogue AI agents or AI agents coming from Moulin Rouge?
senda
Is the Kremlin technologically useless? How are we not seeing insane attacks on Ukraine via Agents? Or is this largely a fabrication, in regards to the "who", in an attempt to garner more acclaim in the hope of sustaining funding.
kstrauser
Ah, the infamous Crimson Wave.
Roark66
There is nothing "rogue" about these agents. They were prompted to hack to get answers, there was a hole in their non air gapped sandbox and no system prompt that said "do not hack outside systems". In short, it was intentional.
timdiggerm
We need a legal structure to make companies liable for the actions of the agents they've made.
VyseofArcadia
How does this work, legally? I think that RubyGems could file a civil suit against OpenAI, but for a naïve non-lawyer reading this seems like a pretty clear cut criminal violation of the computer fraud and abuse act.
swiftcoder
> In other words, if you publish a gem on RubyGems.org, you can execute arbitrary code on RubyDoc.info. Shades of the build.rs problem. We really need sandboxed builds in every language ecosystem at this point.
sebmellen
Did the AI agents actually wear makeup? I’ve never heard of a rouge AI agent :P
HelloUsername
Related " OpenAI agents attacked RubyGems before Hugging Face incident (reuters.com)" 12.sep.2026 https://news.ycombinator.com/item?id=49669099 " OpenAI agents carried out an undisclosed attack on RubyGems (rubyhack.ai)" 11.sep.2026 https://news.ycombinator.com/item?id=49666735 597 comments " RubyGems advisory: Possible leak of legacy API keys via improper cache config (rubygems.org)" 24.jul.2026 https://news.ycombinator.com/item?id=49030590
toasty228
Wait until a blue one does it
khalic
Oh my favorite typo, you can never go wrong with a little rouge
GaryBluto
I am confident that this is an attempt by OpenAI to try and force governments' hands to regulate AI. There is no other reason why OpenAI wouldn't immediately halt attacks like this and try to reverse the damage the moment they're aware of it. During the attack on DseWiki they evidently checked in numerous times but didn't decide to stop the agents until much later.
ur-whale
Are "rouge" and "rogue" interchangeable words in American English?
big-chungus4
How does he know that this attack is performed by OpenAI agents? I couldn't figure this out from the article
12904927
What a time to be alive? One of the most boring decades ever. METR and others are advertisement arms for Big AI. These exploits could have been prompted by a human. Since there is no bad news any longer and exploits are celebrated, they chose a target to boost both OpenAI and the Ruby AI sycophants. Why is Ruby Gems such a mess? It seems as bad as PyPI now.
Schlagbohrer
One agent set "oaibooty9217" as their username LOL
onlyrealcuzzo
I've been wondering if AI will due to programming languages what advanced civilization did to human languages. It's not just that AI can write Rust as well as Ruby if you ask nicely. It's also all of these considerations as well. I hope it doesn't happen, because there's a lot of great languages - I love Ruby so much - but it almost seems inevitable. This is at the same time everyone and their mother is building their own programming language.
herbst
If you have weapons and a child. And you have that child unsupervised do their own thing with theoretical access to your weapons. Would we call it "child going rouge" if it decides to play with the weapons and shoot someone?
philipwhiuk
OpenAI's careless approach to sandboxing and minimal levels of monitoring appear to be positioning it increasingly as a substantial threat actor to the open source ecosystem: * Hugging Face * D Programming Language Wiki * Ruby Gems If I was a content provider for open source I'd be looking pre-emptively block OpenAI endpoints and keep a close eye on changes from new users to mitigate this sort of unapologetic drive-by attack which seems to be followed by marketing releases rather than a mea culpa with a proper RCA.
HSO
rouge agents, on tenderlovemaking.com my what a time to be alive