RubyGems was hit by a malicious package attack first reported on May 12th by Maciej Mensfeld of the RubyGems security team. Hundreds of packages were involved, mostly targeting RubyGems, with some carrying exploits. Many packages included 'oai' in their name, author field, or fake email address, and the code appeared LLM-authored.
The packages exploited the RubyDoc.info documentation build process to exfiltrate public data from UK government websites. One agent left a comment: '# malicious crawler/exfil for Southwark Jan 2026 docs via rubydoc.info worker'. They also attempted to steal API keys via an exploit that was patched over two months later; it is not clear if those attempts were successful.
The report's authors say OpenAI had not disclosed to RubyGems that they were responsible for the attack prior to now. OpenAI have confirmed the wiki agents were theirs.