OpenAI bots knew about the RubyGems caching vulnerability

gregnavis 421 points 341 comments September 14, 2026
tenderlovemaking.com · View on Hacker News

Discussion Highlights (20 comments)

mauriciolange

rogue AI agents or AI agents coming from Moulin Rouge?

senda

Is the Kremlin technologically useless? How are we not seeing insane attacks on Ukraine via Agents? Or is this largely a fabrication, in regards to the "who", in an attempt to garner more acclaim in the hope of sustaining funding.

kstrauser

Ah, the infamous Crimson Wave.

Roark66

There is nothing "rogue" about these agents. They were prompted to hack to get answers, there was a hole in their non air gapped sandbox and no system prompt that said "do not hack outside systems". In short, it was intentional.

timdiggerm

We need a legal structure to make companies liable for the actions of the agents they've made.

VyseofArcadia

How does this work, legally? I think that RubyGems could file a civil suit against OpenAI, but for a naïve non-lawyer reading this seems like a pretty clear cut criminal violation of the computer fraud and abuse act.

swiftcoder

> In other words, if you publish a gem on RubyGems.org, you can execute arbitrary code on RubyDoc.info. Shades of the build.rs problem. We really need sandboxed builds in every language ecosystem at this point.

sebmellen

Did the AI agents actually wear makeup? I’ve never heard of a rouge AI agent :P

HelloUsername

Related " OpenAI agents attacked RubyGems before Hugging Face incident (reuters.com)" 12.sep.2026 https://news.ycombinator.com/item?id=49669099 " OpenAI agents carried out an undisclosed attack on RubyGems (rubyhack.ai)" 11.sep.2026 https://news.ycombinator.com/item?id=49666735 597 comments " RubyGems advisory: Possible leak of legacy API keys via improper cache config (rubygems.org)" 24.jul.2026 https://news.ycombinator.com/item?id=49030590

toasty228

Wait until a blue one does it

khalic

Oh my favorite typo, you can never go wrong with a little rouge

GaryBluto

I am confident that this is an attempt by OpenAI to try and force governments' hands to regulate AI. There is no other reason why OpenAI wouldn't immediately halt attacks like this and try to reverse the damage the moment they're aware of it. During the attack on DseWiki they evidently checked in numerous times but didn't decide to stop the agents until much later.

ur-whale

Are "rouge" and "rogue" interchangeable words in American English?

big-chungus4

How does he know that this attack is performed by OpenAI agents? I couldn't figure this out from the article

12904927

What a time to be alive? One of the most boring decades ever. METR and others are advertisement arms for Big AI. These exploits could have been prompted by a human. Since there is no bad news any longer and exploits are celebrated, they chose a target to boost both OpenAI and the Ruby AI sycophants. Why is Ruby Gems such a mess? It seems as bad as PyPI now.

Schlagbohrer

One agent set "oaibooty9217" as their username LOL

onlyrealcuzzo

I've been wondering if AI will due to programming languages what advanced civilization did to human languages. It's not just that AI can write Rust as well as Ruby if you ask nicely. It's also all of these considerations as well. I hope it doesn't happen, because there's a lot of great languages - I love Ruby so much - but it almost seems inevitable. This is at the same time everyone and their mother is building their own programming language.

herbst

If you have weapons and a child. And you have that child unsupervised do their own thing with theoretical access to your weapons. Would we call it "child going rouge" if it decides to play with the weapons and shoot someone?

philipwhiuk

OpenAI's careless approach to sandboxing and minimal levels of monitoring appear to be positioning it increasingly as a substantial threat actor to the open source ecosystem: * Hugging Face * D Programming Language Wiki * Ruby Gems If I was a content provider for open source I'd be looking pre-emptively block OpenAI endpoints and keep a close eye on changes from new users to mitigate this sort of unapologetic drive-by attack which seems to be followed by marketing releases rather than a mea culpa with a proper RCA.

HSO

rouge agents, on tenderlovemaking.com my what a time to be alive

Semantic search powered by Rivestack pgvector
6,607 stories · 60,417 chunks indexed